TenableCVE-2026-19628
Tenable Security Center: command injection
High8.6CVE-2026-19628 · Published Aug 14, 2026 · updated Aug 19, 2026
A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution on the underlying operating system when specific backend operations are triggered.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Security Center Product | < 6.9.0 | 6.9.0 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-78
More Tenable advisories
All Tenable| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 14 | Tenable Security Center: improper access control | Medium5.3 | 6.9.0 |
| Aug 14 | Tenable Security Center: command injection | High8.7 | 6.9.0 |
| Aug 14 | Tenable Security Center: SQL injection | High7.1 | 6.9.0 |
| Aug 14 | Tenable Security Center: command injection | Critical9.4 | 6.9.0 |
| Aug 14 | Tenable Security Center: command injection | Critical9.4 | 6.9.0 |
| Aug 14 | Tenable Security Center: privilege escalation | High8.6 | 6.9.0 |