Tenable Nessus < 10.12.5 Multiple Vulnerabilities (TNS-2026-26)

high Nessus Plugin ID 362484

Synopsis

An instance of Nessus installed on the remote system is affected by multiple vulnerabilities.

Description

According to its self-reported version, the Tenable Nessus application running on the remote host is prior to 10.12.5.
It is, therefore, affected by multiple vulnerabilities as referenced in the TNS-2026-26 advisory.

- Nessus did not sufficiently verify the integrity of certain downloaded content before using it, which could allow an authenticated, privileged attacker to compromise the system. (CVE-2026-103947)

- An SQL injection vulnerability could allow an authenticated user to read or modify data stored by Nessus.
(CVE-2026-103946)

- Improper handling of inconsistent length values could allow an authenticated, privileged attacker to compromise the confidentiality, integrity or availability of Nessus. (CVE-2026-103948)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Tenable Nessus 10.12.5 or later.

See Also

https://docs.tenable.com/release-notes/Content/nessus/2026.htm

https://www.tenable.com/security/TNS-2026-26

Plugin Details

Severity: High

ID: 362484

File Name: nessus_TNS-2026-26.nasl

Version: 1.1

Type: Combined

Agent: windows, macosx, unix

Family: Misc.

Published: 10/2/2026

Updated: 10/2/2026

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus Agent, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.36

CVSS v2

Risk Factor: Medium

Base Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS Score Source: CVE-2026-103947

CVSS v3

Risk Factor: High

Base Score: 7.2

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/a:tenable:nessus

Required KB Items: installed_sw/Tenable Nessus

Patch Publication Date: 10/1/2026

Vulnerability Publication Date: 10/1/2026

Reference Information

CVE: CVE-2026-103946, CVE-2026-103947, CVE-2026-103948, CVE-2026-103950, CVE-2026-103951, CVE-2026-103952, CVE-2026-103953, CVE-2026-103954, CVE-2026-103955