Description
A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbitrary SQL queries, potentially resulting in unauthorized access to sensitive data, including credentials.
Published: 2026-08-14
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A SQL injection flaw exists in Tenable Security Center that enables an authenticated administrator to run arbitrary SQL statements against the system’s database. The vulnerability can lead to unauthorized read or modification of data, including stored credentials, thereby compromising confidentiality and integrity of the collector’s sensitive data.

Affected Systems

The flaw affects Tenable, Inc.’s Security Center. All installations running before the release of version 6.9.0 are potentially vulnerable, as the vendor’s advisory identifies 6.9.0 as the first patched release.

Risk and Exploitability

The CVSS base score of 6.9 signals a moderate impact. Exploitation requires administrator-level credentials; therefore the threat is limited to environments where such access can be obtained, either through credential compromise or insider activity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread public exploitation at the time of this analysis.

Generated by OpenCVE AI on August 14, 2026 at 18:22 UTC.

Remediation

Vendor Solution

Tenable has released Security Center 6.9.0 to address these issues. The installation files can be obtained from the Tenable Downloads Portal:  https://www.tenable.com/downloads/security-center


OpenCVE Recommended Actions

  • Upgrade to Tenable Security Center 6.9.0 or later to apply the vendor’s fix
  • Restrict database access permissions, ensuring no user other than the core service or audit processes can execute arbitrary SQL
  • Review or disable administrative functionalities that allow raw SQL execution, and enforce role‑based access controls for database operations

Generated by OpenCVE AI on August 14, 2026 at 18:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Tenable
Tenable security Center
Vendors & Products Tenable
Tenable security Center

Fri, 14 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Description A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbitrary SQL queries, potentially resulting in unauthorized access to sensitive data, including credentials.
Title SQL Injection
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Tenable Security Center
cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published:

Updated: 2026-08-14T17:43:45.670Z

Reserved: 2026-08-12T16:02:39.098Z

Link: CVE-2026-19631

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-14T18:17:22.683

Modified: 2026-08-14T18:17:22.683

Link: CVE-2026-19631

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T21:00:05Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')