CVE-2026-19629

Summary

A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission on a single group to modify users belonging to other groups. This bypasses the intended access control restrictions and enables unauthorized cross-group user management.

Affected Software

VendorProductVersion RangeStatus
Tenable, Inc.Security Center0 < 6.9.0affected

Weaknesses

  • CWE-863: CWE-863 (Incorrect Authorization)

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References