Full Report
Tenable, Inc. security advisory (AV26-773)
Analysis Summary
# Vulnerability: Tenable Sensor Proxy Improper Access Control
## CVE Details
- **CVE ID:** CVE-2026-3112
- **CVSS Score:** 7.5 (High)
- **CWE:** CWE-284 (Improper Access Control) / CWE-200 (Exposure of Sensitive Information)
## Affected Systems
- **Products:** Tenable Sensor Proxy
- **Versions:** All versions prior to 1.4.2
- **Configurations:** Systems utilizing Sensor Proxy to manage communication between Nessus scanners/agents and Tenable Vulnerability Management (TVM) or Tenable Security Center (TSC).
## Vulnerability Description
A vulnerability exists in Tenable Sensor Proxy due to improper access control mechanisms. An unauthenticated, remote attacker could potentially exploit this flaw by sending specially crafted requests to the Sensor Proxy service. If successful, the attacker could gain unauthorized access to sensitive configuration data or internal proxy information, leading to information disclosure.
## Exploitation
- **Status:** Not currently reported as exploited in the wild; PoC not publicly released.
- **Complexity:** Low
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High (Unauthorized access to sensitive system/proxy data)
- **Integrity:** None
- **Availability:** None
## Remediation
### Patches
Tenable has released the following version to address this vulnerability:
- **Sensor Proxy 1.4.2** or later.
### Workarounds
There are no documented functional workarounds. Administrators are strongly advised to upgrade to the latest version immediately to mitigate the risk.
## Detection
- **Indicators of compromise:** Monitor web server/proxy logs for unusual or high-frequency requests originating from unrecognized external IP addresses targeting proxy configuration endpoints.
- **Detection methods and tools:**
- Utilize Tenable's own plugins (if updated) to identify outdated Sensor Proxy installations.
- Verify the version of the installed Sensor Proxy using the command line: `sensorproxy --version`.
## References
- [Vendor Advisory: TNS-2026-21] hxxps[://]www[.]tenable[.]com/security/tns-2026-21
- [Tenable Product Security Advisories] hxxps[://]www[.]tenable[.]com/security
- [Cyber Centre Advisory AV26-773] hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/tenable-inc-security-advisory-av26-773