CVE-2026-19679

8.8

Tenable · Security Center

Tenable Security Center is vulnerable to OS command injection due to insufficient sanitization of filenames during file upload operations.

Executive summary

An authenticated OS command injection vulnerability in Tenable Security Center allows attackers to execute arbitrary system commands via crafted file uploads.

Vulnerability

This vulnerability (CWE-78) occurs when the application fails to properly neutralize special characters in file upload requests. An authenticated user can leverage this weakness to inject and execute system-level commands on the Tenable Security Center appliance.

Business impact

The vulnerability carries a CVSS score of 8.8, reflecting its potential for total system impact. Unauthorized command execution could allow an attacker to gain full control over the Tenable Security Center instance, potentially leading to the theft of sensitive vulnerability data or the compromise of administrative credentials used to manage the security infrastructure.

Remediation

Immediate Action: Upgrade to Tenable Security Center version 6.9.0 or later, which is officially released to mitigate this specific command injection vulnerability.

Proactive Monitoring: Review audit logs for suspicious file upload activity and monitor for unexpected spawned processes or shell commands originating from the web server user account.

Compensating Controls: Restrict access to the file upload functionality to trusted administrators only and employ WAF rules to sanitize or block uploads containing suspicious shell metacharacters.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Tenable Security Center is a critical component of security operations, making this vulnerability particularly sensitive. Organizations must prioritize the update to version 6.9.0 to protect their vulnerability management environment from potential exploitation.

More Tenable CVEs