CVE-2026-19628

A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution on the underlying operating system when specific backend operations are triggered.
References
Link Resource
https://www.tenable.com/security/tns-2026-22 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:tenable:security_center:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-14 17:17

Updated : 2026-08-19 17:12


NVD link : CVE-2026-19628

Mitre link : CVE-2026-19628

CVE.ORG link : CVE-2026-19628


JSON object : View

Products Affected

tenable

  • security_center
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')