Changeflow GovPing Data Privacy & Cybersecurity Tenable OT Platform Vulnerability Allows Data C...
Priority review Notice Added Final

Tenable OT Platform Vulnerability Allows Data Confidentiality Breach

Favicon for www.cert.ssi.gouv.fr CERT-FR Security Advisories
Published March 25th, 2026
Detected March 25th, 2026
Email

Summary

CERT-FR has issued a security advisory regarding a vulnerability in Tenable OT Platform. The vulnerability, identified as CVE-2026-4433, can lead to a breach of data confidentiality. Affected systems are versions prior to 4.2.40 without the specific security patch.

What changed

CERT-FR, the French national cybersecurity agency, has published an advisory (CERTFR-2026-AVI-0351) detailing a critical vulnerability (CVE-2026-4433) discovered in Tenable OT Platform. This vulnerability poses a risk of data confidentiality breaches for users running versions prior to 4.2.40 that have not applied the tenable-ot-platform-137 security patch. The advisory references Tenable's security bulletin tns-2026-9 from March 19, 2026, as the source of information.

Organizations utilizing Tenable OT Platform should immediately verify their version and patch status. If affected, immediate action is required to apply the security patch provided by Tenable to mitigate the risk of data confidentiality compromise. Failure to do so could expose sensitive operational technology data to unauthorized access. Compliance officers should ensure their IT security teams are aware of this advisory and have implemented the necessary remediation steps.

What to do next

  1. Verify Tenable OT Platform version and patch status.
  2. Apply security patch tenable-ot-platform-137 if running affected versions.
  3. Consult Tenable's security bulletin tns-2026-9 for detailed remediation steps.

Source document (simplified)

Premier Ministre S.G.D.S.N

Agence nationale
de la sécurité des
systèmes d'information

Paris, le 25 mars 2026 N° CERTFR-2026-AVI-0351 Affaire suivie par: CERT-FR

Avis du CERT-FR

Objet: Vulnérabilité dans Tenable OT Platform

Gestion du document

| Référence | CERTFR-2026-AVI-0351 |
| Titre | Vulnérabilité dans Tenable OT Platform |
| Date de la première version | 25 mars 2026 |
| Date de la dernière version | 25 mars 2026 |
| Source(s) | Bulletin de sécurité Tenable tns-2026-9 du 19 mars 2026 |
Une gestion de version détaillée se trouve à la fin de ce document.


Risque

  • Atteinte à la confidentialité des données

Systèmes affectés

  • OT Platform versions antérieures à 4.2.40 sans le correctif de sécurité tenable-ot-platform-137

Résumé

Une vulnérabilité a été découverte dans Tenable OT Platform. Elle permet à un attaquant de provoquer une atteinte à la confidentialité des données.

Solutions

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

Documentation


Gestion détaillée du document

  1. le 25 mars 2026 Version initiale

Named provisions

Risque Systèmes affectés Résumé Solutions Documentation

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
CERT-FR
Published
March 25th, 2026
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Substantive
Document ID
CERTFR-2026-AVI-0351

Who this affects

Applies to
Technology companies
Industry sector
5112 Software & Technology
Activity scope
Vulnerability Management Data Security
Geographic scope
France FR

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Compliance frameworks
NIST CSF
Topics
Data Privacy Product Security

Get Data Privacy & Cybersecurity alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when CERT-FR Security Advisories publishes new changes.

Free. Unsubscribe anytime.