CVE-2026-15265
CRITICALTenable Agent Path Traversal Leading to Remote Code Execution
Title source: cnaDescription
A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intended plugin directory, potentially leading to remote code execution.
References (1)
Core 1
Core References
Scores
CVSS v3
9.1
EPSS
0.0046
EPSS Percentile
37.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-22
CWE-347
Status
published
Products (2)
tenable/tenable_agent
< 11.1.3
tenable/tenable_agent
11.2.0
Published
Jul 14, 2026
Tracked Since
Jul 14, 2026