CVE-2026-64879

A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality.
References
Link Resource
https://www.tenable.com/security/tns-2026-19 Patch Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:tenable:security_center:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-21 20:17

Updated : 2026-08-18 17:57


NVD link : CVE-2026-64879

Mitre link : CVE-2026-64879

CVE.ORG link : CVE-2026-64879


JSON object : View

Products Affected

tenable

  • security_center

linux

  • linux_kernel
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')