CVE-2026-103952

high

Description

Several vulnerabilities have been identified, reported to Tenable and resolved. Please see the full list of resolved issues below.IssueCVE ID    Severity      CVSS v3 Base/TemporalCVSS v3 VectorAn SQL injection vulnerability could allow an authenticated user to read or modify data stored by Nessus.CVE-2026-103946High8.3 / 7.7CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L/E:F/RL:O/RC:CNessus did not sufficiently verify the integrity of certain downloaded content before using it, which could allow an authenticated, privileged attacker to compromise the system.CVE-2026-103947Critical9.1 / 8.4CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:F/RL:O/RC:CImproper handling of inconsistent length values could allow an authenticated, privileged attacker to compromise the confidentiality, integrity or availability of Nessus.CVE-2026-103948High7.2 / 6.7CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:CA type confusion vulnerability could allow an authenticated, privileged attacker to compromise the confidentiality, integrity or availability of Nessus.CVE-2026-103950High7.2 / 6.7CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:CAn out-of-bounds write vulnerability could allow an authenticated, privileged attacker to compromise the confidentiality, integrity or availability of Nessus.CVE-2026-103951High7.2 / 6.7CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:CAn out-of-bounds write vulnerability could allow an authenticated, privileged attacker to cause a denial of service in Nessus.CVE-2026-103952Medium4.9 / 4.6CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H/E:F/RL:O/RC:CA memory management vulnerability could allow an authenticated, privileged attacker to cause a denial of service in Nessus.CVE-2026-103953Medium4.9 / 4.6CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H/E:F/RL:O/RC:CAn out-of-bounds read vulnerability could allow an authenticated, privileged attacker to disclose limited information from Nessus.CVE-2026-103954Low2.7 / 2.5CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N/E:F/RL:O/RC:CInadequate limits on resource consumption could allow an authenticated, privileged attacker to cause a denial of service in Nessus.CVE-2026-103955Medium4.9 / 4.6CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H/E:F/RL:O/RC:C Tenable has released Nessus version 10.12.5 to address these issues. The installation files can be obtained from the Tenable Downloads Portal (https://www.tenable.com/downloads/nessus).

Details

Source: Mitre, NVD

Published: 2026-10-01

Risk Information

CVSS v2

Base Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 7.2

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Severity: High