TenableCVE-2026-64881
Tenable Security Center: command injection
High8.7CVE-2026-64881 · Published Jul 21, 2026 · updated Aug 18, 2026
The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection when chained with a related vulnerability.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Security Center Product | < 6.8.0 | 6.8.0 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-78
More Tenable advisories
All Tenable| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 29 | Tenable Link Library: cross-site scripting | Medium6.4 | 7.9.4 |
| Jul 21 | Tenable Security Center: remote code execution | Critical9.4 | 6.8.0 |
| Jul 21 | Tenable: command injection | Critical9.4 | No fix yet |
| Jul 21 | Tenable Security Center: SQL injection | High7.1 | 6.8.0 |
| Jul 21 | Tenable: SQL injection | Critical9.4 | No fix yet |
| Jul 14 | tenable_agent: path traversal | Critical9.4 | No fix yet |