CVE-2026-19635
published 2026-08-14CVE-2026-19635: A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific configuration file could achieve arbitrary…
PriorityP348high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.13%
3.1th percentile
A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific configuration file could achieve arbitrary code execution with elevated privileges, without requiring further user or victim interaction.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| tenable | security_center | < 6.9.0 | 6.9.0 |
| tenable_inc | security_center | < 6.9.0 | 6.9.0 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv4.08.5HIGHCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Tenable Security Center up to 6.8.x privileges management
vuldb·2026-08-14·CVSS 8.8
CVE-2026-19635 [HIGH] Tenable Security Center up to 6.8.x privileges management
A vulnerability was found in Tenable Security Center up to 6.8.x and classified as very critical. This impacts an unknown function. Executing a manipulation can lead to improper privilege management.
This vulnerability appears as CVE-2026-19635. The attack requires local access. There is no available exploit.
It is suggested to upgrade the affected component.
GHSA
A local privilege escalation vulnerability exists in Security Center.
ghsa_unreviewed·2026-08-14
CVE-2026-19635 [HIGH] CWE-78 A local privilege escalation vulnerability exists in Security Center.
A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific configuration file could achieve arbitrary code execution with elevated privileges, without requiring further user or victim interaction.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-14
Published