A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission on a single group to modify users belonging to other groups. This bypasses the intended access control restrictions and enables unauthorized cross-group user management.
References
| Link | Resource |
|---|---|
| https://www.tenable.com/security/tns-2026-22 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-08-14 18:17
Updated : 2026-08-19 17:10
NVD link : CVE-2026-19629
Mitre link : CVE-2026-19629
CVE.ORG link : CVE-2026-19629
JSON object : View
Products Affected
tenable
- security_center
CWE
CWE-863
Incorrect Authorization
