CVE-2026-33694 Details
Description
This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges. As a result, this condition potentially facilitates arbitrary code execution, whereby an attacker may exploit the vulnerability to execute malicious code with elevated SYSTEM privileges.
A vulnerability exists in Tenable Nessus versions 10.11.3 and earlier, as well as Nessus Agent on Windows versions 11.1.2 and earlier. This vulnerability allows an attacker to create a junction that can delete arbitrary files with SYSTEM privileges. Consequently, this could lead to arbitrary code execution, as the attacker might exploit this vulnerability to run malicious code with elevated SYSTEM rights.
Users can upgrade to Tenable Nessus versions 10.11.4 or 10.12.0, or to Nessus Agent version 11.1.3. The installation files are available from the Tenable Downloads Portal.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://tenable.com/security/tns-2026-12 | [email protected] | Vendor Advisory |
| https://tenable.com/security/tns-2026-13 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-59 | Improper Link Resolution Before File Access ('Link Following') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| tenable nessus | <= 10.11.3 |
CPE
Remediation
| |
| tenable nessus agent | <= 11.1.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 21, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 23, 2026 | New CVE Received | [email protected] |