CVE-2026-64881
EUVD-2026-4639721.07.2026, 21:16
The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection when chained with a related vulnerability.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| tenable | security_center | 6.6.0 ≤ 𝑥 ≤ 6.8.0 |
𝑥
= Vulnerable software versions