Impact
A privilege escalation flaw in Tenable Security Center lets a user with the Security Manager role and manage user access to a single group modify user accounts in other groups, bypassing intended access control. The vulnerability is a direct access control weakness (CWE‑863) that can lead to unauthorized changes to accounts, compromising both the integrity of user data and the confidentiality of group boundaries. Attacks can elevate privileges within the system, potentially enabling attackers to gain broader administrative capabilities by manipulating user settings across multiple groups.
Affected Systems
The vulnerability affects Tenable Security Center installations prior to version 6.9.0. Tenable has made the 6.9.0 release available to address these issues. All other versions, especially those still carrying the original role and permission checks, remain vulnerable.
Risk and Exploitability
The CVSS score of 8.6 classifies this flaw as high severity, and although no EPSS score is provided, the lack of inclusion in the CISA KEV catalog suggests exploitation has not yet been observed in the wild. The attack path requires authenticated access as a Security Manager with the manage user permission on at least one group; the attacker must then target a different group’s accounts. Consequently, the risk is significant to environments where a single privileged user could affect multiple groups. Prompt remediation is recommended given the high CVSS and the serious potential for cross‑group account compromise.
OpenCVE Enrichment