CVE-2026-19629
8.1Tenable · Security Center
Tenable Security Center contains a privilege escalation flaw allowing users with Security Manager roles to modify users outside their assigned groups.
Executive summary
A privilege escalation vulnerability in Tenable Security Center allows authenticated users to bypass authorization controls and modify user accounts across restricted groups.
Vulnerability
This is an incorrect authorization vulnerability (CWE-863) where a user with the Security Manager role and limited group management permissions can escalate their privileges to perform unauthorized administrative actions on users in other groups.
Business impact
This flaw allows a malicious insider or a compromised account to expand their influence within the security management platform. With a CVSS score of 8.1, this represents a significant risk to internal governance and the principle of least privilege, as unauthorized users could potentially modify or disable security audit accounts.
Remediation
Immediate Action: Upgrade Tenable Security Center to version 6.9.0 or later by downloading the update from the Tenable Downloads Portal.
Proactive Monitoring: Audit user activity logs for unexpected modifications to administrative accounts or changes to group membership configurations.
Compensating Controls: Strictly enforce the principle of least privilege by auditing existing user roles and removing unnecessary "manage user" permissions until the patch is applied.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations should treat this privilege escalation vulnerability with high urgency. Administrators must apply the version 6.9.0 update as soon as possible to restore proper authorization boundaries and prevent unauthorized access to sensitive security management functions.