T
Threats
Tenable Security Center Critical Vulnerabilities
Overview
CVE: CVE-2026-64877, CVE-2026-64878, CVE-2026-64879
Severity: Critical
Date: 22 July 2026
Tenable, Inc. has disclosed three critical vulnerabilities in Security Center, all rated CVSS 9.4. The flaws enable SQL injection, remote code execution, and command injection, with two exploitable by low-privileged users. Organisations running Security Center should patch immediately to prevent data exposure and system compromise.
Affected Versions
See vendor advisory for affected versions.
Vulnerability Breakdown
CVE-2026-64877 – SQL Injection
Severity: Critical
CVSS: 9.4
Description: An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API.
Impact: Unauthorised access to sensitive data stored in the appliance database.
Conditions: Requires authenticated, non-admin access to the ticketing REST API.
CVE-2026-64878 – Command Injection via Asset Filter Parameters
Severity: Critical
CVSS: 9.4
Description: Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling via the Analysis REST endpoint.
Impact: Remote code execution as a low-privileged OS user.
Conditions: Requires access to the Analysis REST endpoint.
CVE-2026-64879 – Command Injection via File Upload
Severity: Critical
CVSS: 9.4
Description: A filename supplied during file upload is not properly sanitised before use in a system command, allowing shell metacharacter injection via the audit file upload functionality.
Impact: Command injection with potential for full system compromise.
Conditions: Requires access to the audit file upload functionality.
Mitigation
Apply the latest Tenable Security Center patch addressing CVE-2026-64877, CVE-2026-64878, and CVE-2026-64879 immediately.
Restrict REST API and file upload access to trusted, authenticated users only.
Review ticketing, Analysis, and audit file upload logs for signs of exploitation.
Enforce least-privilege access across all Security Center accounts.
Summary for IT Teams
Products: Tenable Security Center
Threat Level: Critical, CVSS 9.4
Action Required: Apply the latest Tenable Security Center patch immediately and restrict access to affected REST API endpoints.
Reference
Need Help?
If your organisation needs assistance assessing or patching Tenable Security Center, the Secure ISS SOC team is ready to help. Call us on 1300 769 460 or get in touch via email.

