---
id: CVE-2026-15265
title: >-
  A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower
  allows a privileged attacker to write arbitrary files outside the intended
  plugin directory, potentially leading to remote code execution.
summary: >-
  A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower
  allows a privileged attacker to write arbitrary files outside the intended
  plugin directory, potentially leading to remote code execution.
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-22
  - CWE-347
vendor: tenable
product: nessus_agent
affected:
  - nessus_agent < 11.1.4
  - nessus_agent = 11.2.0
patched:
  - nessus_agent 11.1.4
published: '2026-07-14'
updated: '2026-08-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15265'
references:
  - url: 'https://www.tenable.com/security/tns-2026-18'
    label: vulnreport@tenable.com
tags:
  - nvd
epss: 0.00557
epssPercentile: 0.4402
ingestedAt: '2026-08-26T14:45:08.050Z'
---

## Overview

A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intended plugin directory, potentially leading to remote code execution.

## Affected

- `nessus_agent < 11.1.4`
- `nessus_agent = 11.2.0`

## Remediation

Upgrade past the affected range:

- `nessus_agent 11.1.4`
