CVE-2026-19626
published 2026-08-14CVE-2026-19626: A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could…
PriorityP274critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EXPLOIT
EPSS
1.44%
71.4th percentile
A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted input that is later processed unsafely during server-side report rendering, resulting in arbitrary code execution with the privileges of the service account.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| tenable | security_center | < 6.9.0 | 6.9.0 |
| tenable_inc | security_center | < 6.9.0 | 6.9.0 |
CVSS provenance
nvdv3.19.9CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv4.09.4CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A remote code execution vulnerability exists in Tenable Security Center's report generation functionality.
ghsa_unreviewed·2026-08-14
CVE-2026-19626 [CRITICAL] CWE-95 A remote code execution vulnerability exists in Tenable Security Center's report generation functionality.
A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted input that is later processed unsafely during server-side report rendering, resulting in arbitrary code execution with the privileges of the service account.
VulDB
Tenable Security Center up to 6.8.x Report Generation code injection
vuldb·2026-08-14·CVSS 9.9
CVE-2026-19626 [CRITICAL] Tenable Security Center up to 6.8.x Report Generation code injection
A vulnerability labeled as critical has been found in Tenable Security Center up to 6.8.x. Affected by this issue is some unknown functionality of the component Report Generation. Such manipulation leads to code injection.
This vulnerability is referenced as CVE-2026-19626. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
No detection rules found.
No writeups or analysis indexed.
2026-08-14
Published