CVE-2026-2630

8.8

Tenable · Security Center

A command injection vulnerability in Tenable Security Center allows an authenticated remote attacker to execute arbitrary code on the underlying server.

Executive summary

Tenable Security Center is vulnerable to a critical command injection flaw that allows authenticated remote attackers to execute arbitrary code on the host server.

Vulnerability

This vulnerability is an OS command injection (CWE-78) flaw that occurs due to improper neutralization of special elements in commands. It requires the attacker to have low-level authenticated access to the application.

Business impact

The ability for an attacker to execute arbitrary code on the host server presents a severe risk of full system compromise. Given the CVSS score of 8.8, this vulnerability is classified as High severity, as it could lead to unauthorized data access, lateral movement within the network, or complete control over the security management infrastructure.

Remediation

Immediate Action: Administrators must apply the Tenable Security Center Patch SC-202602.2 available through the Tenable Downloads Portal.

Proactive Monitoring: Security teams should review system access logs for suspicious command executions and monitor for unusual service account behavior originating from the Security Center host.

Compensating Controls: Ensure that the Tenable Security Center instance is isolated within a restricted network segment and that access is strictly limited to authorized personnel to reduce the likelihood of malicious exploitation by authenticated users.

Exploitation status

Public Exploit Available: No (exploit_available: false).

Analyst recommendation

The risk of remote code execution within a security management platform like Tenable Security Center necessitates immediate attention. Organizations should verify their current version and apply the vendor-provided patch without delay to prevent potential system-wide compromise.

More Tenable CVEs

Sources

Originally found and disclosed by Bernard Santillan, OSC Technical Solutions, per the CVE Program record.