---
id: CVE-2026-4433
title: >-
  An SSH misconfigurations exists in Tenable OT that led to the potential
  exfiltration of socket, port, and service information via the ostunnel user
  and GatewayPorts
summary: >-
  An SSH misconfigurations exists in Tenable OT that led to the potential
  exfiltration of socket, port, and service information via the ostunnel user
  and GatewayPorts. This could be used to potentially glean information about
  the underlyin…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'
cwe:
  - CWE-16
vendor: tenable
product: operational_technology_exposure
affected:
  - 'operational_technology_exposure >= 3.18.58, < 4.2.40'
patched:
  - operational_technology_exposure 4.2.40
published: '2026-03-24'
updated: '2026-08-18'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-4433'
references:
  - url: 'https://www.tenable.com/security/tns-2026-9'
    label: vulnreport@tenable.com
tags:
  - nvd
epss: 0.00164
epssPercentile: 0.06079
ingestedAt: '2026-08-18T20:22:14.587Z'
---

## Overview

An SSH misconfigurations exists in Tenable OT that led to the potential exfiltration of socket, port, and service information via the ostunnel user and GatewayPorts. This could be used to potentially glean information about the underlying system and give an attacker information that could be used to attempt to compromise the host.

## Affected

- `operational_technology_exposure >= 3.18.58, < 4.2.40`

## Remediation

Upgrade past the affected range:

- `operational_technology_exposure 4.2.40`
