CVE-2026-2697Authorization Bypass Through User-Controlled Key in Security Center

Severity
5.3MEDIUMNVD
EPSS
0.1%
top 67.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 23

Description

An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges via the 'owner' parameter.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Packages2 packages

CVEListV5tenable/security_center< 6.8.0

🔴Vulnerability Details

2
CVEList
Indirect Object Reference (IDOR) in Security Center2026-02-23
GHSA
GHSA-6pjc-995p-mh58: An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges via the 'owner' parameter2026-02-23
CVE-2026-2697 — Tenable Security Center vulnerability | cvebase