CVE-2026-19628
7.2Tenable · Security Center
Tenable Security Center versions prior to 6.9.0 contain an OS command injection vulnerability that allows authenticated administrators to execute arbitrary commands on the underlying host.
Executive summary
A command injection vulnerability in Tenable Security Center prior to version 6.9.0 allows authenticated users with high privileges to execute arbitrary OS commands.
Vulnerability
The application is susceptible to OS command injection (CWE-78) due to improper neutralization of special elements. This vulnerability requires the attacker to be authenticated with high privileges, limiting the initial vector of attack to compromised or malicious administrative accounts.
Business impact
Successful exploitation grants an attacker full control over the underlying operating system of the Security Center instance. With a CVSS score of 7.2, the potential for total system compromise, exfiltration of vulnerability data, or pivoting into the wider network environment poses a severe risk to organizational security.
Remediation
Immediate Action: Update Tenable Security Center to version 6.9.0 or later immediately. The update can be obtained through the official Tenable Downloads Portal.
Proactive Monitoring: Review administrative audit logs for unusual command execution patterns or unauthorized changes to system configurations.
Compensating Controls: Ensure that administrative access to the Security Center interface is restricted to highly trusted personnel and monitored via multi-factor authentication.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Organizations should treat this as a high-priority update. Apply the 6.9.0 patch immediately to eliminate the risk of command injection and ensure that administrative access is strictly managed and audited.