CVE-2026-64881

HIGH

Tenable, Inc. Security Center < 6.8.0 - Command Injection

Title source: rule
STIX 2.1

Description

The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection when chained with a related vulnerability.

References (1)

Core 1

Scores

CVSS v3 8.8
EPSS 0.0144
EPSS Percentile 70.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
Tenable, Inc./Security Center < 6.8.0
Published Jul 21, 2026
Tracked Since Jul 22, 2026