Skip to content
TenableCVE-2026-64879

Tenable: command injection

Critical9.4CVE-2026-64879 · Published Jul 21, 2026 · updated Aug 18, 2026

A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality.

Tenable advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-78

More Tenable advisories

All Tenable
Advisory
Tenable Link Library: cross-site scripting
Medium6.4Jul 29
Tenable Security Center: command injection
High8.7Jul 21
Tenable Security Center: remote code execution
Critical9.4Jul 21
Tenable Security Center: SQL injection
High7.1Jul 21
Tenable: SQL injection
Critical9.4Jul 21
tenable_agent: path traversal
Critical9.4Jul 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.