Skip to content
TenableCVE-2026-19682

Tenable Security Center: command injection

Critical9.4CVE-2026-19682 · Published Aug 14, 2026 · updated Aug 19, 2026

A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating system with the privileges of the service account.

Tenable advisory

Affected versions

PackageAffectedFixed in
Security Center
Product
< 6.9.06.9.0
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-78

More Tenable advisories

All Tenable
Advisory
Tenable Security Center: improper access control
Medium5.3Aug 14
Tenable Security Center: command injection
High8.7Aug 14
Tenable Security Center: SQL injection
High7.1Aug 14
Tenable Security Center: command injection
Critical9.4Aug 14
Tenable Security Center: privilege escalation
High8.6Aug 14
Tenable Security Center: SQL injection
Medium6.9Aug 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.