CVE-2026-4433: Tenable Operational Technology Exposure
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
An SSH misconfigurations exists in Tenable OT that led to the potential exfiltration of socket, port, and service information via the ostunnel user and GatewayPorts. This could be used to potentially glean information about the underlying system and give an attacker information that could be used to attempt to compromise the host.
Affected products
- Tenable Operational Technology Exposure: from 3.18.58, before 4.2.40 (fixed in 4.2.40)
Published 2026-03-24. Last modified 2026-08-18.