TenableCVE-2026-15265
tenable_agent: path traversal
Critical9.4CVE-2026-15265 · Published Jul 14, 2026 · updated Aug 25, 2026
A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intended plugin directory, potentially leading to remote code execution.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| tenable_agent Product | <= 11.2.0 | No fix yet |
| <= 11.1.3 | No fix yet |
Details and references
More Tenable advisories
All Tenable| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 29 | Tenable Link Library: cross-site scripting | Medium6.4 | 7.9.4 |
| Jul 21 | Tenable Security Center: command injection | High8.7 | 6.8.0 |
| Jul 21 | Tenable Security Center: SQL injection | High7.1 | 6.8.0 |
| Jul 21 | Tenable: command injection | Critical9.4 | No fix yet |
| Jul 21 | Tenable Security Center: remote code execution | Critical9.4 | 6.8.0 |
| Jul 21 | Tenable: SQL injection | Critical9.4 | No fix yet |