CVE-2026-15265

A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intended plugin directory, potentially leading to remote code execution.
References
Link Resource
https://www.tenable.com/security/tns-2026-18 Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:tenable:nessus_agent:*:*:*:*:*:*:*:*
cpe:2.3:a:tenable:nessus_agent:11.2.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-14 15:16

Updated : 2026-08-25 20:47


NVD link : CVE-2026-15265

Mitre link : CVE-2026-15265

CVE.ORG link : CVE-2026-15265


JSON object : View

Products Affected

tenable

  • nessus_agent
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-347

Improper Verification of Cryptographic Signature