A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality.
References
| Link | Resource |
|---|---|
| https://www.tenable.com/security/tns-2026-19 | Patch Third Party Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2026-07-21 20:17
Updated : 2026-08-18 17:57
NVD link : CVE-2026-64879
Mitre link : CVE-2026-64879
CVE.ORG link : CVE-2026-64879
JSON object : View
Products Affected
tenable
- security_center
linux
- linux_kernel
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
