nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-4433 CVE-2026-4433
LOW
Tenable OT SSH Misconfiguration Information Disclosure
Record summary
CVE-2026-4433 has a selected CVSS score of 1.9 (low).
Description
An SSH misconfigurations exists in Tenable OT that led to the potential exfiltration of socket, port, and service information via the ostunnel user and GatewayPorts. This could be used to potentially glean information about the underlying system and give an attacker information that could be used to attempt to compromise the host.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 25, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Tenable Operation TechnologyBrowse Tenable, Inc. / Tenable Operation TechnologyDefault status: unaffected | CVE List | 3.18.58 to ≤ 4.2.40 | affected |
References
2tenable.com
https://www.tenable.com/security/tns-2026-9