Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4498 articles · 223866 vulns · 37/41 feeds (7d)
← Back to list
9.9
CVE-2026-64878PATCHED
tenable · security center

Command Injection

Description

Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user via the Analysis REST endpoint.

Affected Products

VendorProductVersions
tenablesecurity center0

References

  • https://www.tenable.com/security/tns-2026-19

Related News (5 articles)

Tier B
CERT-FR49d ago
Bulletin d'actualité CERTFR-2026-ACT-034 (10 août 2026)
→ No new info (linked only)
Tier B
CERT-FR55d ago
Multiples vulnérabilités dans les produits Tenable (04 août 2026)
→ No new info (linked only)
Tier B
CERT-FR63d ago
Bulletin d'actualité CERTFR-2026-ACT-032 (27 juillet 2026)
→ No new info (linked only)
Tier C
VulDB68d ago
CVE-2026-64878 | Tenable Security Center up to 6.7.x Asset filter asset filter os command injection
→ No new info (linked only)
Tier B
CERT-FR69d ago
Multiples vulnérabilités dans Tenable Security Center (21 juillet 2026)
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.9 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
6.8.0
CWECWE-78
PublishedJul 21, 2026
Last enriched68d agov2
Trending Score0
Source articles5
Independent2
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-18667
Sensor Proxy Version 1.4.2 Fixes One Vulnerability
Trending: 6
CRITICALCVE-2026-19626
Remote Code Execution
Trending: 5
HIGHCVE-2026-19628
Remote Code Execution
Trending: 2
CRITICALCVE-2026-19681
Command Injection
CRITICALCVE-2026-19682
Command Injection

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 21, 2026
Discovered by ZDM
Jul 21, 2026
Updated: affectedVersions
Jul 21, 2026
Patch Available
Jul 24, 2026

Version History

v2
Last enriched 68d ago
v2Tier C68d ago

Updated affected versions to include 6.7.x in addition to version 0

affectedVersions
via VulDB
v168d ago

Initial creation