Impact
An authenticated, non-administrative user can supply specially crafted input that is later processed unsafely during server-side report rendering, leading to arbitrary code execution with the privileges of the service account. This flaw exemplifies CWE‑95, the classic Code Injection weakness, where maliciously crafted data is executed as code. The vulnerability allows the attacker to run malicious code on the Tenable Security Center server, potentially compromising all data and operations managed by the platform.
Affected Systems
Tenable, Inc. Security Center is affected. The issue is documented against versions prior to Security Center 6.9.0; the 6.9.0 release contains the fix.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.4, indicating a critical severity. Although an EPSS score is not available, the lack of KEV listing does not reduce the attack potential. The attacker must be authenticated but not an administrator, so the exploit requires legitimate user credentials, yet it results in code execution with service‑account privileges, exposing the entire system to compromise. The remote nature of the attack vector combined with the high impact suggests a high likelihood of exploitation by resourceful threat actors.
OpenCVE Enrichment