CVE-2026-64879: A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve comm
A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-64879
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2026-648792.6% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 84% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-64879 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMultiple vulnerabilities in Tenable products (August 4, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in Tenable Security Center (July 21, 2026)cert-fr-avis
Recent advisories for A filename supplied
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalCVE-2026-52680: Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename…nvd · 2026-07-30
- mediumCVE-2026-16743: A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-…nvd · 2026-07-24
- criticalCVE-2026-52891: Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionalit…nvd · 2026-07-15
- highCVE-2026-12511: The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before …nvd · 2026-07-14
- criticalCVE-2026-14480: OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy …nvd · 2026-07-10
More from NVD Recent CVEs
- highCVE-2026-19190: A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part …2026-08-07
- unknownCVE-2026-49746: Software installed and run as a non-privileged user may conduct improper GPU system calls to c…2026-08-07
- unknownCVE-2026-45204: Software installed and run as a non-privileged user may conduct improper GPU system calls to t…2026-08-07
- unknownCVE-2026-45198: Kernel software from a non-secure operating system on a platform with Trusted Execution Enviro…2026-08-07
- highCVE-2026-19189: A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue …2026-08-07