Tenable Security Center vulnerabilities
10 known vulnerabilities affecting tenable/security_center.
Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM6LOW1
Vulnerabilities
Page 1 of 1
CVE-2026-2698MEDIUMCVSS 5.7fixed in 6.8.02026-02-23
CVE-2026-2698 [MEDIUM] CWE-639 CVE-2026-2698: An improper access control vulnerability exists where an authenticated user could access areas outsi
An improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope.
cvelistv5nvd
CVE-2026-2697MEDIUMCVSS 5.3fixed in 6.8.02026-02-23
CVE-2026-2697 [MEDIUM] CWE-639 CVE-2026-2697: An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to es
An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges via the 'owner' parameter.
cvelistv5nvd
CVE-2026-2630HIGHCVSS 7.4≤ 6.7.22026-02-17
CVE-2026-2630 [HIGH] CWE-78 CVE-2026-2630: A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbit
A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the underlying server where Tenable Security Center is hosted.
cvelistv5nvd
CVE-2025-36636MEDIUMCVSS 4.3fixed in 6.7.02025-10-08
CVE-2025-36636 [MEDIUM] CWE-284 CVE-2025-36636: In Tenable Security Center versions prior to 6.7.0, an improper access control vulnerability exists
In Tenable Security Center versions prior to 6.7.0, an improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope.
cvelistv5nvd
CVE-2024-12174LOWCVSS 2.7fixed in 6.5.02024-12-09
CVE-2024-12174 [LOW] CWE-295 CVE-2024-12174: An Improper Certificate Validation vulnerability exists in Tenable Security Center where an authenti
An Improper Certificate Validation vulnerability exists in Tenable Security Center where an authenticated, privileged attacker could intercept email messages sent from Security Center via a rogue SMTP server.
cvelistv5nvd
CVE-2024-5759MEDIUMCVSS 6.3≤ 6.3.0fixed in 6.4.02024-06-12
CVE-2024-5759 [MEDIUM] CWE-269 CVE-2024-5759: An improper privilege management vulnerability exists in Tenable Security Center where an authentica
An improper privilege management vulnerability exists in Tenable Security Center where an authenticated, remote attacker could view unauthorized objects and launch scans without having the required privileges
cvelistv5nvd
CVE-2024-1891MEDIUMCVSS 5.4fixed in 6.4.02024-06-12
CVE-2024-1891 [MEDIUM] CWE-79 CVE-2024-1891: A stored cross site scripting vulnerability exists in Tenable Security Center where an authenticated
A stored cross site scripting vulnerability exists in Tenable Security Center where an authenticated, remote attacker could inject HTML code into a web application scan result page.
cvelistv5nvd
CVE-2024-1367HIGHCVSS 7.2fixed in 6.3.02024-02-14
CVE-2024-1367 [HIGH] CWE-78 CVE-2024-1367:
A command injection vulnerability exists where an authenticated, remote attacker with administrator
A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Logging parameters, which could lead to the execution of arbitrary code on the Security Center host.
cvelistv5nvd
CVE-2024-1471MEDIUMCVSS 4.8fixed in 6.3.02024-02-14
CVE-2024-1471 [MEDIUM] CWE-20 CVE-2024-1471:
An HTML injection vulnerability exists where an authenticated, remote attacker with administrator p
An HTML injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Repository parameters, which could lead to HTML redirection attacks.
cvelistv5nvd
CVE-2023-2005HIGHCVSS 8.8fixed in Plugin Feed ID #202306261202 2023-06-26
CVE-2023-2005 [HIGH] CWE-427 CVE-2023-2005: Vulnerability in Tenable Tenable.Io, Tenable Nessus, Tenable Security Center.This issue affects Tena
Vulnerability in Tenable Tenable.Io, Tenable Nessus, Tenable Security Center.This issue affects Tenable.Io: before Plugin Feed ID #202306261202 ; Nessus: before Plugin Feed ID #202306261202 ; Security Center: before Plugin Feed ID #202306261202 .
This vulnerability could allow a malicious actor with sufficient permissions on a scan target to place a bi
cvelistv5nvd