CVE-2026-19681

9.9

Tenable · Security Center

An authenticated command injection vulnerability exists in Tenable Security Center during file upload processing, allowing arbitrary command execution.

Executive summary

An authenticated command injection vulnerability in Tenable Security Center allows an attacker to execute arbitrary commands on the underlying operating system, posing a severe risk to infrastructure security.

Vulnerability

This is a command injection vulnerability (CWE-78) triggered during file upload processes. An authenticated user can supply malicious input that is improperly neutralized, resulting in OS command execution.

Business impact

With a CVSS score of 9.9, successful exploitation allows an attacker to gain full control over the server hosting Security Center. This could result in the compromise of sensitive vulnerability data, lateral movement within the network, and total loss of confidentiality, integrity, and availability.

Remediation

Immediate Action: Update Tenable Security Center to version 6.9.0 or later using the files provided in the Tenable Downloads Portal.

Proactive Monitoring: Monitor system logs for unexpected child processes or unusual file activity originating from the Security Center service.

Compensating Controls: Ensure that the Security Center instance is isolated via network controls and strictly limit the number of users with upload privileges.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations utilizing Tenable Security Center must prioritize upgrading to version 6.9.0 immediately. Given the high severity and the potential for full system compromise, this should be handled as an emergency maintenance task.

More Tenable CVEs