Junglewise Threat Intelligence

CVE-2026-64879: Tenable Security Center command injection in audit file upload

CVE-2026-64879 · Severity: critical · CVSS 9.9 · Published 2026-07-21

Technologies: Tenable, Inc. Security Center.

Executive brief

Tenable Security Center, a platform used by organizations to manage and track security vulnerabilities, contains a critical flaw in its audit file upload feature. An attacker with basic user permissions can exploit this to take full control of the underlying server. This could lead to the theft of sensitive security data, disruption of vulnerability management operations, or a complete system takeover.

Technical details

A command injection vulnerability exists in Tenable Security Center due to improper sanitization of filenames during the audit file upload process. An authenticated attacker with low privileges can supply a crafted filename containing shell metacharacters, which are subsequently executed by the system during command execution. This allows for arbitrary code execution with the privileges of the application. The vulnerability affects versions prior to 6.8.0 and has been addressed in patch SC202607.1.

Affected products

  • Tenable, Inc. Security Center < 6.8.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory
  • 2026-07-21: patched: Patch SC202607.1 released

References