CVE-2026-19682
published 2026-08-14CVE-2026-19682: A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on…
PriorityP179critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
2.84%
85.7th percentile
A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating system with the privileges of the service account.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| tenable | security_center | < 6.9.0 | 6.9.0 |
| tenable_inc | security_center | < 6.9.0 | 6.9.0 |
CVSS provenance
nvdv3.19.9CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv4.09.4CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Tenable Security Center up to 6.8.x command injection
vuldb·2026-08-14·CVSS 9.9
CVE-2026-19682 [CRITICAL] Tenable Security Center up to 6.8.x command injection
A vulnerability was found in Tenable Security Center up to 6.8.x. It has been declared as very critical. This vulnerability affects unknown code. Such manipulation leads to command injection.
This vulnerability is traded as CVE-2026-19682. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
GHSA
A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating system with the
ghsa_unreviewed·2026-08-14
CVE-2026-19682 [CRITICAL] CWE-78 A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating system with the
A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating system with the privileges of the service account.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-14
Published