CVE-2026-3493

high

Description

A path traversal vulnerability exists in Nessus Manager where an authenticated, remote attacker could read arbitrary OS system files.  Tenable has released Nessus Manager versions 10.10.3 and 10.11.3 to address these issues. The installation files can be obtained from the Tenable Downloads Portal (https://www.tenable.com/downloads/nessus).

Details

Source: Mitre, NVD

Published: 2026-03-03

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Severity: High