TenableCVE-2026-64879
Tenable: command injection
Critical9.4CVE-2026-64879 · Published Jul 21, 2026 · updated Aug 18, 2026
A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-78
More Tenable advisories
All Tenable| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 29 | Tenable Link Library: cross-site scripting | Medium6.4 | 7.9.4 |
| Jul 21 | Tenable Security Center: command injection | High8.7 | 6.8.0 |
| Jul 21 | Tenable Security Center: remote code execution | Critical9.4 | 6.8.0 |
| Jul 21 | Tenable Security Center: SQL injection | High7.1 | 6.8.0 |
| Jul 21 | Tenable: SQL injection | Critical9.4 | No fix yet |
| Jul 14 | tenable_agent: path traversal | Critical9.4 | No fix yet |