Executive brief
Tenable Security Center, a platform used for managing and prioritizing organizational cyber risk, contains a vulnerability in its audit file upload component. An attacker with low-level user access can upload files with specially crafted names to execute unauthorized commands on the underlying system. This could lead to a full system takeover, data theft, or disruption of security operations.
Technical details
An OS command injection vulnerability (CWE-78) exists in Tenable Security Center's audit file upload handler. The component fails to properly sanitize filenames, allowing shell metacharacters to be passed directly into system command execution. While the vulnerability requires low-privileged authentication (PR:L), it can be chained with other flaws to achieve remote code execution on the host operating system. The issue affects versions prior to 6.8.0 and is addressed in patch SC202607.1.
Affected products
- Tenable, Inc. Security Center < 6.8.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory
- 2026-07-21: patched: Patch SC202607.1 released