CVE-2026-19626
A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted input that is later processed unsafely during server-side report rendering, resulting in arbitrary code execution with the privileges of the service account.
- Affected products
- Tenable Security Center
- Tenable Security Center
- < 6.9.0
- CVSS 3.1
- 9.9 CRITICAL
- EPSS
- 0.5% (40th percentile)
- Weakness
- CWE-95
- NVD status
- Analyzed
- Published
- 2026-08-14
Fix
Tenable has released Security Center 6.9.0 to address these issues. The installation files can be obtained from the Tenable Downloads Portal:Â https://www.tenable.com/downloads/security-center
CVE-2026-19626 at NVD
3 known exploits for CVE-2026-19626
Proof-of-concept code and exploit modules indexed by Sploitus