Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Tenable has released Security Center Patch SC202607.1 to address these issues. The installation files can be obtained from the Tenable Downloads Portal: https://www.tenable.com/downloads/security-center
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.tenable.com/security/tns-2026-19 |
|
Thu, 23 Jul 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenable
Tenable security Center |
|
| Vendors & Products |
Tenable
Tenable security Center |
Wed, 22 Jul 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 21 Jul 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection when chained with a related vulnerability. | |
| Title | Command Injection | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2026-07-24T03:55:55.735Z
Reserved: 2026-07-20T19:19:24.798Z
Link: CVE-2026-64881
Updated: 2026-07-22T19:33:32.678Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-24T03:15:02Z