CVE-2026-19626
9.9Tenable · Security Center
Tenable Security Center is vulnerable to remote code execution during report generation, allowing an authenticated, non-administrative user to execute arbitrary code on the server.
Executive summary
A critical remote code execution vulnerability in Tenable Security Center allows an authenticated, low-privileged user to execute arbitrary code with service account privileges.
Vulnerability
This is an eval injection vulnerability occurring within the report generation functionality. An authenticated user can supply malicious input during the server-side rendering process, which results in the execution of arbitrary code with the privileges of the underlying service account.
Business impact
Successful exploitation allows an attacker to gain remote code execution capabilities on the host system. This can lead to total system compromise, unauthorized access to sensitive vulnerability data, and the potential for lateral movement within the network. Although the attack requires authentication, the high CVSS score of 9.9 reflects the extreme impact of arbitrary code execution on a security management platform.
Remediation
Immediate Action: Update Tenable Security Center to version 6.9.0 or later, which is available via the Tenable Downloads Portal.
Proactive Monitoring: Monitor server logs for suspicious activities during report generation or unexpected process execution spawned by the Security Center service.
Compensating Controls: Limit access to the Security Center interface to trusted users only and ensure the application is segmented within the network to minimize potential lateral movement.
Exploitation status
Public Exploit Available: No (unknown)
Analyst recommendation
Given the critical nature of this remote code execution vulnerability, organizations should treat the update to version 6.9.0 as a high-priority task. Applying the patch is the only effective method to mitigate the risk of unauthorized system-level command execution.