- Description
- A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality.
- Source
- vulnreport@tenable.com
- NVD status
- Analyzed
- Products
- security_center
CVSS 4.0
- Type
- Secondary
- Base score
- 9.4
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
CVSS 3.1
- Type
- Secondary
- Base score
- 9.9
- Impact score
- 6
- Exploitability score
- 3.1
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- vulnreport@tenable.com
- CWE-78
- Hype score
- Not currently trending
šØ CERT-FR is highlighting three critical Tenable Security Center vulnerabilities: ⢠CVE-2026-64877 ā SQL injection ⢠CVE-2026-64878 ā RCE ⢠CVE-2026-64879 ā RCE All three carry a CVSS score of 9.4. #Tenable #VulnerabilityManagement #CVE Source: CERT-FR, 27 Jul 20
@XQOPTRX
27 Jul 2026
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Warning: #Tenable Security Center is affected by multiple high-severity vulnerabilities! Critical #CVE-2026-64879 (CVSS:9.9) and CVE-2026-64878 (CVSS:9.9) both allow attackers to inject commands leading to #RCE! Tenable advisory at: https://t.co/RmoGelqMrw #Patch #Patch #Patch
@CCBalert
27 Jul 2026
189 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:tenable:security_center:*:*:*:*:*:*:*:*",
"matchCriteriaId": "976FA116-4533-441B-BC65-FC30D4E13F6C",
"versionEndIncluding": "6.8.0",
"versionStartIncluding": "6.6.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*",
"matchCriteriaId": "703AF700-7A70-47E2-BC3A-7FD03B3CA9C1",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
}
]