Junglewise Threat Intelligence

CVE-2026-19679: Tenable Security Center file upload command injection

CVE-2026-19679 · Severity: high · CVSS 8.8 · Published 2026-08-14

Vendors: Tenable.

Executive brief

Tenable Security Center, a vulnerability management platform used to scan and assess network security, contains an input validation flaw in file upload handling that could allow authenticated attackers to execute arbitrary system commands. Successful exploitation could grant an attacker complete control over the affected system, leading to data breach, system compromise, and operational disruption.

Technical details

The vulnerability is an OS command injection flaw resulting from insufficient sanitization of uploaded filenames in Security Center's file upload handling. The attack vector is network-based and requires authentication (PR:L); no user interaction is needed. An authenticated attacker can craft a malicious filename containing shell metacharacters that, when processed by the backend, executes arbitrary commands with the privileges of the Security Center service. The vulnerability affects Security Center versions prior to 6.9.0, which includes the fix. CVSS 8.8 (high severity) reflects the ability to achieve high impact on confidentiality, integrity, and availability.

Affected products

  • Tenable Security Center before 6.9.0

Timeline

  • 2026-08-14: disclosed
  • 2026-08-14: patched: Security Center 6.9.0 released

References