CVE-2026-19682

9.9

Tenable · Security Center

A command injection vulnerability exists in Tenable Security Center, allowing remote authenticated attackers to execute arbitrary system commands via an insecurely handled input parameter.

Executive summary

A critical command injection vulnerability in Tenable Security Center allows authenticated attackers to execute arbitrary system commands with service account privileges.

Vulnerability

The software fails to properly neutralize special elements used in an operating system command. This flaw allows a remote attacker with low-level privileges to inject malicious commands that execute with the permissions of the underlying service account.

Business impact

Successful exploitation of this vulnerability leads to full system compromise, as the attacker can run arbitrary commands with the privileges of the service account. Given the CVSS score of 9.9, this represents a critical risk to the confidentiality, integrity, and availability of the Tenable platform and any data managed by it. Unauthorized access could lead to lateral movement within the network or the exfiltration of sensitive vulnerability assessment data.

Remediation

Immediate Action: Upgrade Tenable Security Center to version 6.9.0 or later immediately. Installation files are available through the official Tenable Downloads Portal.

Proactive Monitoring: Review system logs for suspicious process execution, particularly those originating from the Security Center service user. Monitor for unauthorized changes to system configuration files or unexpected outbound network traffic.

Compensating Controls: Implement strict network segmentation to limit access to the Security Center management interface to authorized administrative segments only. Utilize host-based intrusion detection systems to flag unauthorized command-line activity.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability necessitates immediate attention from security teams. Organizations should prioritize the upgrade to version 6.9.0 to eliminate the command injection vector and prevent potential compromise of the management infrastructure.

More Tenable CVEs