Description
A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating system with the privileges of the service account.
Published: 2026-08-14
Score: 9.4 Critical
EPSS: 2.8% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A command injection flaw allows a remote, unauthenticated attacker to inject and execute arbitrary operating‑system commands with the privileges of the Service Center service account. This weakness, identified as CWE‑78, enables the attacker to exfiltrate data, modify or delete files, install persistent backdoors, and potentially take full control of the host if successful. The vulnerability exists within the Security Center platform and has no authentication guard in the interface that accepts user input for system commands.

Affected Systems

The affected product is Tenable, Inc.: Security Center. All installations released before version 6.9.0 are vulnerable. No specific operating‑system constraints are mentioned, implying all supported OS editions of pre‑6.9.0 builds are at risk.

Risk and Exploitability

The CVSS base score is 9.4, indicating a critical level of severity. EPSS score is 2%, indicating a low yet non‑zero probability for exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no public exploitation yet. However, the attack vector is remote and does not require any authentication, making the threat highly actionable. An attacker who can reach the exposed interface can execute OS commands directly, with a high likelihood of achieving the impact described if no mitigation is in place.

Generated by OpenCVE AI on August 15, 2026 at 21:38 UTC.

Remediation

Vendor Solution

Tenable has released Security Center 6.9.0 to address these issues. The installation files can be obtained from the Tenable Downloads Portal: https://www.tenable.com/downloads/security-center


OpenCVE Recommended Actions

  • Apply the vendor patch by installing Tenable Security Center 6.9.0 from the Tenable Downloads Portal.
  • If patching immediately is not possible, isolate the affected systems from the network and restrict all external access to the Security Center interface until the update is applied.
  • Implement network‑level controls such as firewall rules to block inbound traffic to the Security Center on vulnerable ports from untrusted networks during the interim period before patching.

Generated by OpenCVE AI on August 15, 2026 at 21:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:tenable:security_center:*:*:*:*:*:*:*:*

Sat, 15 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 14 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Tenable
Tenable security Center
Vendors & Products Tenable
Tenable security Center

Fri, 14 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Description A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating system with the privileges of the service account.
Title Command Injection
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Tenable Security Center
cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published:

Updated: 2026-08-15T03:55:57.656Z

Reserved: 2026-08-12T22:42:42.220Z

Link: CVE-2026-19682

cve-icon Vulnrichment

Updated: 2026-08-14T18:54:46.047Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-14T18:17:23.623

Modified: 2026-08-19T16:46:51.960

Link: CVE-2026-19682

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-15T21:45:02Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')