A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution on the underlying operating system when specific backend operations are triggered.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.tenable.com/security/tns-2026-22 |
|
History
Sat, 15 Aug 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 14 Aug 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenable
Tenable security Center |
|
| Vendors & Products |
Tenable
Tenable security Center |
Fri, 14 Aug 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution on the underlying operating system when specific backend operations are triggered. | |
| Title | Remote Code Execution | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: tenable
Published: 2026-08-14T17:00:01.858Z
Updated: 2026-08-15T03:55:53.158Z
Reserved: 2026-08-12T15:39:11.627Z
Link: CVE-2026-19628
Updated: 2026-08-14T17:27:21.383Z
Status : Received
Published: 2026-08-14T17:17:31.110
Modified: 2026-08-15T04:18:18.847
Link: CVE-2026-19628
No data.