Tenable OT Platform Vulnerability Allows Data Confidentiality Breach
Summary
CERT-FR has issued a security advisory regarding a vulnerability in Tenable OT Platform. The vulnerability, identified as CVE-2026-4433, can lead to a breach of data confidentiality. Affected systems are versions prior to 4.2.40 without the specific security patch.
What changed
CERT-FR, the French national cybersecurity agency, has published an advisory (CERTFR-2026-AVI-0351) detailing a critical vulnerability (CVE-2026-4433) discovered in Tenable OT Platform. This vulnerability poses a risk of data confidentiality breaches for users running versions prior to 4.2.40 that have not applied the tenable-ot-platform-137 security patch. The advisory references Tenable's security bulletin tns-2026-9 from March 19, 2026, as the source of information.
Organizations utilizing Tenable OT Platform should immediately verify their version and patch status. If affected, immediate action is required to apply the security patch provided by Tenable to mitigate the risk of data confidentiality compromise. Failure to do so could expose sensitive operational technology data to unauthorized access. Compliance officers should ensure their IT security teams are aware of this advisory and have implemented the necessary remediation steps.
What to do next
- Verify Tenable OT Platform version and patch status.
- Apply security patch tenable-ot-platform-137 if running affected versions.
- Consult Tenable's security bulletin tns-2026-9 for detailed remediation steps.
Source document (simplified)
Premier Ministre S.G.D.S.N
Agence nationale
de la sécurité des
systèmes d'information
Paris, le 25 mars 2026 N° CERTFR-2026-AVI-0351 Affaire suivie par: CERT-FR
Avis du CERT-FR
Objet: Vulnérabilité dans Tenable OT Platform
Gestion du document
| Référence | CERTFR-2026-AVI-0351 |
| Titre | Vulnérabilité dans Tenable OT Platform |
| Date de la première version | 25 mars 2026 |
| Date de la dernière version | 25 mars 2026 |
| Source(s) | Bulletin de sécurité Tenable tns-2026-9 du 19 mars 2026 |
Une gestion de version détaillée se trouve à la fin de ce document.
Risque
- Atteinte à la confidentialité des données
Systèmes affectés
- OT Platform versions antérieures à 4.2.40 sans le correctif de sécurité tenable-ot-platform-137
Résumé
Une vulnérabilité a été découverte dans Tenable OT Platform. Elle permet à un attaquant de provoquer une atteinte à la confidentialité des données.
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
Documentation
- Bulletin de sécurité Tenable tns-2026-9 du 19 mars 2026
- https://www.tenable.com/security/tns-2026-9
- Référence CVE CVE-2026-4433
- https://www.cve.org/CVERecord?id=CVE-2026-4433
Gestion détaillée du document
- le 25 mars 2026 Version initiale
Named provisions
Related changes
Source
Classification
Who this affects
Taxonomy
Browse Categories
Get Data Privacy & Cybersecurity alerts
Weekly digest. AI-summarized, no noise.
Free. Unsubscribe anytime.
Get alerts for this source
We'll email you when CERT-FR Security Advisories publishes new changes.