CVE-2026-19626

A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted input that is later processed unsafely during server-side report rendering, resulting in arbitrary code execution with the privileges of the service account.
References
Link Resource
https://www.tenable.com/security/tns-2026-22 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:tenable:security_center:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-14 17:17

Updated : 2026-08-19 17:04


NVD link : CVE-2026-19626

Mitre link : CVE-2026-19626

CVE.ORG link : CVE-2026-19626


JSON object : View

Products Affected

tenable

  • security_center
CWE
CWE-95

Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')