Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4356 articles · 196349 vulns · 36/41 feeds (7d)
← Back to list
9.9
CVE-2026-64878PATCHED
tenable · security center

Command Injection

Description

Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user via the Analysis REST endpoint.

Affected Products

VendorProductVersions
tenablesecurity center0

References

  • https://www.tenable.com/security/tns-2026-19

Related News (5 articles)

Tier B
CERT-FR14d ago
Bulletin d'actualité CERTFR-2026-ACT-034 (10 août 2026)
→ No new info (linked only)
Tier B
CERT-FR20d ago
Multiples vulnérabilités dans les produits Tenable (04 août 2026)
→ No new info (linked only)
Tier B
CERT-FR28d ago
Bulletin d'actualité CERTFR-2026-ACT-032 (27 juillet 2026)
→ No new info (linked only)
Tier C
VulDB33d ago
CVE-2026-64878 | Tenable Security Center up to 6.7.x Asset filter asset filter os command injection
→ No new info (linked only)
Tier B
CERT-FR34d ago
Multiples vulnérabilités dans Tenable Security Center (21 juillet 2026)
→ No new info (linked only)
CVSS 3.19.9 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
6.8.0
CWECWE-78
PublishedJul 21, 2026
Last enriched33d agov2
Trending Score10
Source articles5
Independent2
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-19681
Command Injection
Trending: 11
CRITICALCVE-2026-19682
Command Injection
Trending: 11
CRITICALCVE-2026-64879
Command Injection
Trending: 10
CRITICALCVE-2026-19626
Remote Code Execution
Trending: 10
HIGHCVE-2026-19628
Remote Code Execution
Trending: 9

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 21, 2026
Discovered by ZDM
Jul 21, 2026
Updated: affectedVersions
Jul 21, 2026
Patch Available
Jul 24, 2026

Version History

v2
Last enriched 33d ago
v2Tier C33d ago

Updated affected versions to include 6.7.x in addition to version 0

affectedVersions
via VulDB
v133d ago

Initial creation