CVE-2021-20135: Tenable Nessus

Medium severity, CVSS 6.7. EPSS: 0.3% chance of exploitation in the next 30 days.

Nessus versions 8.15.2 and earlier were found to contain a local privilege escalation vulnerability which could allow an authenticated, local administrator to run specific executables on the Nessus Agent host. Tenable has included a fix for this issue in Nessus 10.0.0. The installation files can be obtained from the Tenable Downloads Portal (https://www.tenable.com/downloads/nessus).

Affected products

  • Tenable Nessus: up to and including 8.15.2

Published 2021-11-03. Last modified 2026-06-17.