CVE-2026-64879

CRITICAL

Tenable, Inc. Security Center < 6.8.0 - Command Injection

Title source: rule
STIX 2.1

Description

A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality.

References (1)

Core 1

Scores

CVSS v3 9.9
EPSS 0.0259
EPSS Percentile 83.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
Tenable, Inc./Security Center < 6.8.0
Published Jul 21, 2026
Tracked Since Jul 22, 2026