CVE-2026-19680
published 2026-08-14CVE-2026-19680: A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database.
PriorityP346high7.1CVSS 3.1
AVNACLPRLUINSUCHILAN
EPSS
0.23%
14.0th percentile
A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| tenable | security_center | < 6.9.0 | 6.9.0 |
| tenable_inc | security_center | < 6.9.0 | 6.9.0 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
nvdv4.07.1HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database.
ghsa_unreviewed·2026-08-14
CVE-2026-19680 [HIGH] CWE-89 A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database.
A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database.
VulDB
Tenable Security Center up to 6.8.x sql injection
vuldb·2026-08-14·CVSS 7.1
CVE-2026-19680 [HIGH] Tenable Security Center up to 6.8.x sql injection
A vulnerability described as critical has been identified in Tenable Security Center up to 6.8.x. The affected element is an unknown function. The manipulation results in sql injection.
This vulnerability is identified as CVE-2026-19680. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-14
Published