cbcvebase.

Tenable Inc Security Center vulnerabilities

14 known vulnerabilities affecting tenable_inc/security_center.

Total CVEs
14
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH7MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2026-19681P2CRITICALCVSS 9.9PoCfixed in 6.9.02026-08-14
CVE-2026-19681 [CRITICAL] CWE-78 CVE-2026-19681: An authenticated command injection vulnerability exists in Security Center related to file upload pr An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially crafted file, potentially resulting in arbitrary command execution on the underlying operating system.
nvd
CVE-2026-19626P2CRITICALCVSS 9.9PoCfixed in 6.9.02026-08-14
CVE-2026-19626 [CRITICAL] CWE-95 CVE-2026-19626: A remote code execution vulnerability exists in Tenable Security Center's report generation function A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted input that is later processed unsafely during server-side report rendering, resulting in arbitrary code execution with the privileges of the serv
nvd
CVE-2026-19682P1CRITICALCVSS 9.9fixed in 6.9.02026-08-14
CVE-2026-19682 [CRITICAL] CWE-78 CVE-2026-19682: A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating system with the privileges of the service account.
nvd
CVE-2026-64878P2CRITICALCVSS 9.9fixed in 6.8.02026-07-21
CVE-2026-64878 [CRITICAL] CWE-78 CVE-2026-64878: Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user via the Analysis REST endpoint.
nvd
CVE-2026-64881P2HIGHCVSS 8.8fixed in 6.8.02026-07-21
CVE-2026-64881 [HIGH] CWE-78 CVE-2026-64881: The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow int The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection when chained with a related vulnerability.
nvd
CVE-2026-19679P2HIGHCVSS 8.8fixed in 6.9.02026-08-14
CVE-2026-19679 [HIGH] CWE-78 CVE-2026-19679: An input validation vulnerability exists in Security Center's file upload handling, where insufficie An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitization of uploaded filenames could contribute to a downstream command injection issue.
nvd
CVE-2026-19628P3HIGHCVSS 7.2fixed in 6.9.02026-08-14
CVE-2026-19628 [HIGH] CWE-78 CVE-2026-19628: A command injection vulnerability exists in Tenable Security Center. An authenticated administrator A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution on the underlying operating system when specific backend operations are triggered.
nvd
CVE-2026-19629P3HIGHCVSS 8.1fixed in 6.9.02026-08-14
CVE-2026-19629 [HIGH] CWE-863 CVE-2026-19629: A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Secu A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission on a single group to modify users belonging to other groups. This bypasses the intended access control restrictions and enables unauthorized cross-group user management.
nvd
CVE-2026-19635P3HIGHCVSS 8.8fixed in 6.9.02026-08-14
CVE-2026-19635 [HIGH] CWE-78 CVE-2026-19635: A local privilege escalation vulnerability exists in Security Center. An attacker with write access A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific configuration file could achieve arbitrary code execution with elevated privileges, without requiring further user or victim interaction.
nvd
CVE-2026-64880P3HIGHCVSS 7.1fixed in 6.8.02026-07-21
CVE-2026-64880 [HIGH] CWE-89 CVE-2026-64880: Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL que Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injection and unauthorized database read access.
nvd
CVE-2026-19680P3HIGHCVSS 7.1fixed in 6.9.02026-08-14
CVE-2026-19680 [HIGH] CWE-89 CVE-2026-19680: A SQL injection vulnerability exists in Security Center that could allow an attacker to access unaut A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database.
nvd
CVE-2026-19631P3MEDIUMCVSS 4.9fixed in 6.9.02026-08-14
CVE-2026-19631 [MEDIUM] CWE-89 CVE-2026-19631: A SQL injection vulnerability exists in Security Center that could allow an authenticated administra A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbitrary SQL queries, potentially resulting in unauthorized access to sensitive data, including credentials.
nvd
CVE-2026-19636P4MEDIUMCVSS 5.3fixed in 6.9.02026-08-14
CVE-2026-19636 [MEDIUM] CWE-1270 CVE-2026-19636: An issue was identified in which CSRF tokens were generated using a predictable method, potentially An issue was identified in which CSRF tokens were generated using a predictable method, potentially reducing their effectiveness as a security control. This has been addressed by improving the randomness and entropy of token generation.
nvd
CVE-2026-19639P4MEDIUMCVSS 4.3fixed in 6.9.02026-08-14
CVE-2026-19639 [MEDIUM] CWE-1284 CVE-2026-19639: An improper access control vulnerability exists where an authenticated non-administrative applicatio An improper access control vulnerability exists where an authenticated non-administrative application user could potentially view settings outside of their assigned scope.
nvd
Tenable Inc Security Center vulnerabilities | cvebase