Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-19626: Tenable Security Center Report Generation Code Execution Risk
CVE-2026-19626 · published 20 days ago
Summary
A security flaw in Tenable Security Center's report generation feature could allow an authorized user to execute malicious code on the system. This could lead to unauthorized access or data compromise. Update to the latest version of Tenable Security Center to mitigate this risk.
What to do
- Update tenable, inc. security center to version 6.9.0 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| tenable, inc. | security center | < 6.9.0 |
Original advisory text
A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially ...
A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted input that is later processed unsafely during server-side report rendering, resulting in arbitrary code execution with the privileges of the service account.
References
Severity
9.4
Critical
CVSS 3.1: 9.9 (NVD)
CVSS 4.0: 9.4 (NVD)
Exploitation
EPSS 1%
Type
CWE-95Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
Timeline
Published14 Aug 2026
Updated30 Aug 2026
First seen14 Aug 2026
Monitor software like this
Free during beta