CVE-2026-4433 Details
Description
An SSH misconfigurations exists in Tenable OT that led to the potential exfiltration of socket, port, and service information via the ostunnel user and GatewayPorts. This could be used to potentially glean information about the underlying system and give an attacker information that could be used to attempt to compromise the host.
A misconfiguration in the SSH settings of Tenable OT versions through 4.2.40 has been identified, allowing the potential exfiltration of socket, port, and service information. This vulnerability arises from the use of the ostunnel user and GatewayPorts, which could be exploited to gather details about the underlying system, potentially leading to a compromise of the host.
Tenable has released a patch named 'tenable-ot-platform-137' to address this vulnerability. This patch is available for currently deployed products. For new installations, the Tenable OT Security and Tenable OT Security Enterprise Manager ISOs released on March 18, 2026, include the fix. These installation files can be downloaded from the Tenable Downloads Portal.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.tenable.com/security/tns-2026-9 | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-16 | Configuration | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| tenable operational technology exposure | >= 3.18.58, < 4.2.40 |
CPE
Remediation
| |
| linux linux kernel | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 18, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Mar 24, 2026 | New CVE Received | [email protected] |