A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality.
References
| Link | Resource |
|---|---|
| https://www.tenable.com/security/tns-2026-19 |
Configurations
No configuration.
History
21 Jul 2026, 20:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-21 20:17
Updated : 2026-07-21 20:17
NVD link : CVE-2026-64879
Mitre link : CVE-2026-64879
CVE.ORG link : CVE-2026-64879
JSON object : View
Products Affected
No product.
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
