{"id":"CVE-2026-4433","title":"An SSH misconfigurations exists in Tenable OT that led to the potential exfiltration of socket, port, and service information via the ostunnel user and GatewayPorts","summary":"An SSH misconfigurations exists in Tenable OT that led to the potential exfiltration of socket, port, and service information via the ostunnel user and GatewayPorts. This could be used to potentially glean information about the underlyin…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","cwe":["CWE-16"],"vendor":"tenable","product":"operational_technology_exposure","affected":["operational_technology_exposure >= 3.18.58, < 4.2.40"],"patched":["operational_technology_exposure 4.2.40"],"published":"2026-03-24","updated":"2026-08-18","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-4433","references":[{"url":"https://www.tenable.com/security/tns-2026-9","label":"vulnreport@tenable.com"}],"tags":["nvd"],"epss":0.00164,"epssPercentile":0.06087,"ingestedAt":"2026-08-18T20:22:14.587Z","slug":"CVE-2026-4433","body":"## Overview\n\nAn SSH misconfigurations exists in Tenable OT that led to the potential exfiltration of socket, port, and service information via the ostunnel user and GatewayPorts. This could be used to potentially glean information about the underlying system and give an attacker information that could be used to attempt to compromise the host.\n\n## Affected\n\n- `operational_technology_exposure >= 3.18.58, < 4.2.40`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `operational_technology_exposure 4.2.40`","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}