CVE-2026-19626

Summary

A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted input that is later processed unsafely during server-side report rendering, resulting in arbitrary code execution with the privileges of the service account.

Affected Software

VendorProductVersion RangeStatus
Tenable, Inc.Security Center0 < 6.9.0affected

Weaknesses

  • CWE-95: CWE-95 Improper neutralization of directives in dynamically evaluated code ('eval injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References