CVE-2026-19681
9.9Tenable · Security Center
An authenticated command injection vulnerability exists in Tenable Security Center during file upload processing, allowing arbitrary command execution.
Executive summary
An authenticated command injection vulnerability in Tenable Security Center allows an attacker to execute arbitrary commands on the underlying operating system, posing a severe risk to infrastructure security.
Vulnerability
This is a command injection vulnerability (CWE-78) triggered during file upload processes. An authenticated user can supply malicious input that is improperly neutralized, resulting in OS command execution.
Business impact
With a CVSS score of 9.9, successful exploitation allows an attacker to gain full control over the server hosting Security Center. This could result in the compromise of sensitive vulnerability data, lateral movement within the network, and total loss of confidentiality, integrity, and availability.
Remediation
Immediate Action: Update Tenable Security Center to version 6.9.0 or later using the files provided in the Tenable Downloads Portal.
Proactive Monitoring: Monitor system logs for unexpected child processes or unusual file activity originating from the Security Center service.
Compensating Controls: Ensure that the Security Center instance is isolated via network controls and strictly limit the number of users with upload privileges.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations utilizing Tenable Security Center must prioritize upgrading to version 6.9.0 immediately. Given the high severity and the potential for full system compromise, this should be handled as an emergency maintenance task.