CVE-2026-64879: Command Injection
A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Tenable Security Centerto a version that resolves this vulnerability.Fixed in 202607.1Patch SC202607.1
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs privileges sufficient to use the audit file upload functionality. The attack can be performed remotely with low complexity and does not require user interaction.
What access does successful exploitation provide?
A malicious filename containing shell metacharacters can cause system command injection. The published severity metrics indicate potential high impact to confidentiality, integrity, and availability, including effects beyond the vulnerable component's security scope.
Are default installations affected?
The available information identifies the audit file upload functionality as the affected attack path, but does not state whether it is enabled or reachable in a default configuration.