PatchSiren

Tenable, Inc. CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Tenable, Inc. CVE published 2026-07-21

CVE-2026-64881

CVE-2026-64881 is a HIGH severity vulnerability with a CVSS score of 8.7. The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection when chained with a related vulnerability. Security teams and administrators responsible for systems using the affected audit file upload handler shou [truncated]

HIGH Tenable, Inc. CVE published 2026-07-21

CVE-2026-64880

CVE-2026-64880 is a high-severity blind SQL injection vulnerability. The issue arises from unsanitized user-supplied input in report filtering parameters being concatenated directly into SQL queries without proper escaping or parameterized queries. This allows for unauthorized database read access. The CVE record was published on 2026-07-21T20:17:04.900Z and was last modified on 2026-07-22T20:35:40.827Z.

CRITICAL Tenable, Inc. CVE published 2026-07-21

CVE-2026-64879

CVE-2026-64879 is a critical vulnerability with a CVSS score of 9.4. A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality. The vulnerability arises from improper sanitization of filenames during file upload, which are then used [truncated]

CRITICAL Tenable, Inc. CVE published 2026-07-21

CVE-2026-64878

CVE-2026-64878 is a critical vulnerability in the Analysis REST endpoint of an affected product, allowing remote code execution as a low-privileged OS user. The vulnerability exists due to unvalidated input in asset filter parameters, which enables shell metacharacters to escape command argument handling. Users of affected products should review their configurations and apply patches or mitigations as ava [truncated]

CRITICAL Tenable, Inc. CVE published 2026-07-21

CVE-2026-64877

CVE-2026-64877 is a SQL injection vulnerability in the ticketing REST API of an appliance. An authenticated non-admin user can exploit this flaw to access sensitive data stored in the appliance database. The CVSS score for this vulnerability is 9.4, indicating a critical severity level. The vulnerability exists due to improper input validation in the ticketing REST API, allowing malicious SQL code injecti [truncated]