CVE-2026-19681
published 2026-08-14CVE-2026-19681: An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading…
PriorityP278critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EXPLOIT
EPSS
7.80%
94.3th percentile
An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially crafted file, potentially resulting in arbitrary command execution on the underlying operating system.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| tenable | security_center | < 6.9.0 | 6.9.0 |
| tenable_inc | security_center | < 6.9.0 | 6.9.0 |
CVSS provenance
nvdv3.19.9CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv4.09.4CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Tenable Security Center up to 6.8.x command injection
vuldb·2026-08-14·CVSS 9.9
CVE-2026-19681 [CRITICAL] Tenable Security Center up to 6.8.x command injection
A vulnerability was found in Tenable Security Center up to 6.8.x. It has been rated as critical. This issue affects some unknown processing. Performing a manipulation results in command injection.
This vulnerability is known as CVE-2026-19681. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
GHSA
An authenticated command injection vulnerability exists in Security Center related to file upload processing.
ghsa_unreviewed·2026-08-14
CVE-2026-19681 [CRITICAL] CWE-78 An authenticated command injection vulnerability exists in Security Center related to file upload processing.
An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially crafted file, potentially resulting in arbitrary command execution on the underlying operating system.
No detection rules found.
2026-08-14
Published