CVE-2026-19635
8.8Tenable · Security Center
Tenable Security Center contains an OS command injection vulnerability, allowing authenticated local users to execute arbitrary commands with elevated privileges.
Executive summary
A local OS command injection vulnerability in Tenable Security Center could allow an authenticated attacker to achieve full system compromise.
Vulnerability
The software fails to properly neutralize special elements used in OS commands (CWE-78), enabling command injection. The attack requires local access and authenticated privileges (PR:L) to execute the malicious payload.
Business impact
With a CVSS score of 8.8, this local privilege escalation vulnerability poses a severe threat to infrastructure security. An attacker who has already gained low-level access to the host can escalate their privileges to perform unauthorized system operations, leading to potential data exfiltration or system destruction.
Remediation
Immediate Action: Upgrade Tenable Security Center to version 6.9.0 or later using the files provided in the Tenable Downloads Portal.
Proactive Monitoring: Monitor system logs for unexpected process execution or shell commands originating from the Security Center service account.
Compensating Controls: Restrict local shell access to the host server and apply the principle of least privilege to all users who have access to the Security Center interface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations should proceed with the update to version 6.9.0 as soon as possible. Because this is a local privilege escalation, securing the underlying operating system and auditing user access rights should be conducted alongside the software patch.