CVE-2026-15265 – Tenable Agent

CVSS 9.1 CRITICAL Critical - Same Day Deployment

“Even trusted components can become dangerous when file boundaries are no longer enforced.”

Tenable has released a security update for Tenable Agent to address CVE-2026-15265, a path traversal vulnerability affecting Tenable Agent 11.2.0 and earlier supported versions. The vulnerability allows a privileged attacker to write arbitrary files outside the intended plugin directory, which could potentially lead to remote code execution. The CVSS score is 9.1, which is Critical severity.

The update strengthens file path validation and plugin handling to prevent unauthorized file writes outside the intended directory. There is no verified evidence of public proof-of-concept code or real-world exploitation associated with this vulnerability.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
CWE Classification
CWE-22
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.