SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-15265

CRITICAL · CVSS 9.1 EPSS 0.46% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

A path traversal vulnerability in Tenable Agent versions 11.2.0 and 11.1.3 and earlier enables privileged attackers to write arbitrary files outside the designated plugin directory, which could result in remote code execution. Organizations using these versions should prioritize patching this vulnerability immediately to mitigate the risk of exploitation. This critical flaw poses a significant threat to systems relying on Tenable Agent for security monitoring.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15265
Severity
CRITICAL
CVSS
9.1
EPSS
0.46%

Original NVD Description

A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intended plugin directory, potentially leading to remote code execution.