Junglewise Threat Intelligence

CVE-2026-64878: Tenable Security Center command injection in Analysis REST endpoint

CVE-2026-64878 · Severity: critical · CVSS 9.9 · Published 2026-07-21

Vendors: Tenable.

Executive brief

Tenable Security Center, a platform used for managing and prioritizing cyber risks, is affected by a critical vulnerability in its Analysis REST endpoint. An attacker with low-level user credentials can exploit this flaw to execute unauthorized commands on the underlying operating system. This could lead to a complete takeover of the security management server, potentially exposing sensitive vulnerability data or disrupting security operations.

Technical details

A command injection vulnerability exists in Tenable Security Center due to improper neutralization of special elements used in OS commands (CWE-78). The flaw is located within the asset filter parameters of the Analysis REST endpoint. An authenticated attacker with low-privileged access can provide specially crafted input containing shell metacharacters to escape command argument handling and execute arbitrary code on the host operating system. The vulnerability has been addressed in patch SC202607.1 for versions 6.6.0, 6.7.2, and 6.8.0.

Affected products

  • Tenable Security Center < 6.8.0

Timeline

  • 2026-07-21: advisory
  • 2026-07-21: disclosed
  • 2026-07-21: patched: Patch SC202607.1 released

References