Junglewise Threat Intelligence

CVE-2026-15265: Tenable Agent path traversal in plugin directory

CVE-2026-15265 · Severity: critical · CVSS 9.1 · Published 2026-07-14

Vendors: Tenable.

Executive brief

Tenable Agent, a software component used to monitor and assess the security of computers and servers, contains a vulnerability that could allow an attacker to take full control of a system. By exploiting a flaw in how the agent handles file paths, a high-privileged attacker can write malicious files to sensitive areas of the operating system. This could lead to remote code execution, potentially resulting in data theft, service disruption, or a complete compromise of the affected machine.

Technical details

A path traversal vulnerability (CWE-22) exists in Tenable Agent versions 11.2.0, 11.1.3, and earlier across Windows, Linux, and macOS platforms. The flaw stems from improper verification of cryptographic signatures (CWE-347) and inadequate path validation, allowing a high-privileged attacker to write arbitrary files outside of the designated plugin directory. While the attack requires high privileges, the vulnerability is reachable over the network and carries a high impact because it can lead to remote code execution (RCE) with a scope break (S:C). Users are advised to update to patched versions of the Tenable Agent.

Affected products

  • Tenable Tenable Agent 11.2.0, 11.1.3 and lower

Timeline

  • 2026-07-14: advisory: Initial publication of the vulnerability details.

References