{"id":"CVE-2026-33694","title":"This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges","summary":"This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges. As a result, this condition potentially facilitates arbitrary code execution, whereby an attacker may exploit th…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-59"],"vendor":"tenable","product":"nessus","affected":["nessus <= 10.11.3","nessus_agent <= 11.1.2"],"published":"2026-04-23","updated":"2026-08-21","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-33694","references":[{"url":"https://tenable.com/security/tns-2026-12","label":"vulnreport@tenable.com"},{"url":"https://tenable.com/security/tns-2026-13","label":"vulnreport@tenable.com"}],"tags":["nvd"],"epss":0.00153,"epssPercentile":0.04784,"ingestedAt":"2026-08-22T01:24:51.081Z","slug":"CVE-2026-33694","body":"## Overview\n\nThis vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges. As a result, this condition potentially facilitates arbitrary code execution, whereby an attacker may exploit the vulnerability to execute malicious code with elevated SYSTEM privileges.\n\n## Affected\n\n- `nessus <= 10.11.3`\n- `nessus_agent <= 11.1.2`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}