Executive brief
Security Center is Tenable's vulnerability management platform used by organizations to scan networks and identify security risks. A local privilege escalation vulnerability allows an attacker with write access to a configuration file to execute arbitrary code with elevated system privileges, bypassing normal security controls and potentially compromising the entire scanning and reporting infrastructure.
Technical details
CVE-2026-19635 is a local privilege escalation vulnerability in Security Center that results from improper handling of configuration file permissions and execution context. An attacker with local write access to a specific configuration file can manipulate its contents to achieve arbitrary code execution with elevated privileges, with no further user interaction required. The attack requires local system access and application-level privileges (PR:L), but escalates to system-wide compromise (S:C). Tenable patched this issue in Security Center 6.9.0.
Affected products
- Tenable Security Center before 6.9.0
Timeline
- 2026-08-14: disclosed
- 2026: patched: Security Center 6.9.0