Junglewise Threat Intelligence

CVE-2026-19639: Tenable Security Center improper access control vulnerability

CVE-2026-19639 · Severity: medium · CVSS 4.3 · Published 2026-08-14

Vendors: Tenable.

Executive brief

Tenable Security Center is a vulnerability management platform used by enterprises to scan and manage security risks across their infrastructure. An authenticated non-administrator user could view configuration settings and data outside of their assigned permissions, potentially exposing sensitive administrative information to lower-privileged staff.

Technical details

This improper access control vulnerability (CVE-2026-19639) allows an authenticated application user without administrative privileges to access settings and data beyond their assigned scope. The vulnerability requires an existing authenticated session (PR:L) and can be exploited over the network without user interaction. An attacker with a standard user account could enumerate and view sensitive configuration details normally restricted to administrators. Tenable addressed this issue in Security Center version 6.9.0.

Affected products

  • Tenable Security Center before 6.9.0

Timeline

  • 2026-08-14: disclosed

References