CVE-2026-19631
published 2026-08-14CVE-2026-19631: A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbitrary SQL queries, potentially resulting…
PriorityP335medium4.9CVSS 3.1
AVNACLPRHUINSUCHINAN
EPSS
0.23%
13.8th percentile
A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbitrary SQL queries, potentially resulting in unauthorized access to sensitive data, including credentials.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| tenable | security_center | < 6.9.0 | 6.9.0 |
| tenable_inc | security_center | < 6.9.0 | 6.9.0 |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Tenable Security Center up to 6.8.x sql injection
vuldb·2026-08-14·CVSS 4.9
CVE-2026-19631 [MEDIUM] Tenable Security Center up to 6.8.x sql injection
A vulnerability has been found in Tenable Security Center up to 6.8.x and classified as problematic. This affects an unknown function. Performing a manipulation results in sql injection.
This vulnerability is reported as CVE-2026-19631. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
GHSA
A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbitrary SQL queries, potentially resulting in unauthorized access to sensitive data
ghsa_unreviewed·2026-08-14
CVE-2026-19631 [MEDIUM] CWE-89 A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbitrary SQL queries, potentially resulting in unauthorized access to sensitive data
A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbitrary SQL queries, potentially resulting in unauthorized access to sensitive data, including credentials.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-14
Published