CVE-2026-19628
published 2026-08-14CVE-2026-19628: A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve…
PriorityP356high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
2.00%
79.2th percentile
A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution on the underlying operating system when specific backend operations are triggered.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| tenable_inc | security_center | < 6.9.0 | 6.9.0 |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.6HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A command injection vulnerability exists in Tenable Security Center.
ghsa_unreviewed·2026-08-14
CVE-2026-19628 [HIGH] CWE-78 A command injection vulnerability exists in Tenable Security Center.
A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution on the underlying operating system when specific backend operations are triggered.
VulDB
Tenable Security Center up to 6.8.x command injection
vuldb·2026-08-14·CVSS 7.2
CVE-2026-19628 [HIGH] Tenable Security Center up to 6.8.x command injection
A vulnerability marked as very critical has been reported in Tenable Security Center up to 6.8.x. This affects an unknown part. Performing a manipulation results in command injection.
This vulnerability is identified as CVE-2026-19628. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-14
Published