Executive brief
Tenable Security Center is a vulnerability management platform used by enterprises to scan and manage security risks across their infrastructure. An authenticated non-administrator user could view configuration settings and data outside of their assigned permissions, potentially exposing sensitive administrative information to lower-privileged staff.
Technical details
This improper access control vulnerability (CVE-2026-19639) allows an authenticated application user without administrative privileges to access settings and data beyond their assigned scope. The vulnerability requires an existing authenticated session (PR:L) and can be exploited over the network without user interaction. An attacker with a standard user account could enumerate and view sensitive configuration details normally restricted to administrators. Tenable addressed this issue in Security Center version 6.9.0.
Affected products
- Tenable Security Center before 6.9.0
Timeline
- 2026-08-14: disclosed