LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-64879

tenable · security center

Published
CVSS9.9
Severitycritical
WeaknessCWE-78
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Description

A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-64879

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-64879.