CVE-2026-15265: Tenable Agent Path Traversal Leading to Remote Code Execution
Published Jul 14, 2026
·Updated
A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intended plugin directory, potentially leading to remote code execution.
Affected Software
1 affected component
Tenable Tenable Agent>=11.1.4<11.2.0
Event History
Jul 14, 2026
CVE Published
via MITRE·03:02 PM
Data Sourced
via MITRE·03:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-15265?
The severity of CVE-2026-15265 is critical with a CVSS score of 9.1.
2
How do I fix CVE-2026-15265?
To fix CVE-2026-15265, upgrade Tenable Agent to version 11.2.0 or higher.
3
What are the potential impacts of CVE-2026-15265?
CVE-2026-15265 can lead to remote code execution by allowing privileged attackers to write arbitrary files.
4
Which versions of Tenable Agent are affected by CVE-2026-15265?
Tenable Agent versions 11.2.0, 11.1.3, and lower are affected by CVE-2026-15265.
5
What type of vulnerability is CVE-2026-15265 categorized as?
CVE-2026-15265 is categorized as a path traversal vulnerability.