Description
An improper access control vulnerability exists where an authenticated non-administrative application user could potentially view settings outside of their assigned scope.
Published: 2026-08-14
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper access control flaw allows an authenticated non-administrative user to view configuration settings that lie outside their intended scope. The vulnerability is a classic example of CWE-1284, where privileges are not enforced correctly. The immediate risk is the exposure of sensitive system configuration, which could aid an attacker in further reconnaissance or exploitation steps.

Affected Systems

Tenable, Inc.'s Security Center product is impacted. All versions prior to Security Center 6.9.0 are potentially vulnerable, as the fix is included in the 6.9.0 release. Users should verify they are running a version newer than 6.8.x to ensure the issue is resolved.

Risk and Exploitability

The CVSS score of 5.3 classifies the flaw as medium severity. Because it requires authentication and is restricted to non-admin users, the attack vector is limited to users who already have legitimate but non-administrative access, either via legitimate credentials or credential compromise. No EPSS data is available, and the vulnerability is not listed in CISA KEV, suggesting there are no known large-scale exploit campaigns targeting it.

Generated by OpenCVE AI on August 14, 2026 at 19:25 UTC.

Remediation

Vendor Solution

Tenable has released Security Center 6.9.0 to address these issues. The installation files can be obtained from the Tenable Downloads Portal:  https://www.tenable.com/downloads/security-center


OpenCVE Recommended Actions

  • Upgrade Tenable Security Center to version 6.9.0 or later.
  • Enforce least-privilege policies to ensure non-admin users are only granted the configuration scopes they need.
  • Review and audit user permissions regularly to detect any over-privileged accounts.

Generated by OpenCVE AI on August 14, 2026 at 19:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 14 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description An improper access control vulnerability exists where an authenticated non-administrative application user could potentially view settings outside of their assigned scope.
Title Improper Access Control
Weaknesses CWE-1284
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published:

Updated: 2026-08-14T18:01:13.504Z

Reserved: 2026-08-12T16:41:08.085Z

Link: CVE-2026-19639

cve-icon Vulnrichment

Updated: 2026-08-14T18:01:10.262Z

cve-icon NVD

Status : Received

Published: 2026-08-14T18:17:23.100

Modified: 2026-08-14T18:17:23.100

Link: CVE-2026-19639

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T19:30:04Z

Weaknesses
  • CWE-1284

    Improper Validation of Specified Quantity in Input