Junglewise Threat Intelligence

CVE-2026-19680: Tenable Security Center SQL injection

CVE-2026-19680 · Severity: high · CVSS 7.1 · Published 2026-08-14

Vendors: Tenable.

Executive brief

Tenable Security Center, a vulnerability management platform used by organizations to identify and manage security risks, contains a SQL injection vulnerability that allows authenticated attackers to access unauthorized data from the application's database. Exploitation could lead to exposure of sensitive security assessment data, including scan results and asset information that could be leveraged for further attacks.

Technical details

A SQL injection vulnerability exists in Security Center that allows authenticated attackers to inject malicious SQL queries into the application. The vulnerability is network-reachable and requires valid login credentials (PR:L). An attacker with access to the application can construct specially crafted inputs to extract sensitive data from the database without authorization. The CVSS vector indicates low impact on integrity (I:L) and no impact on availability. Tenable has patched this issue in Security Center version 6.9.0.

Affected products

  • Tenable Security Center prior to 6.9.0

Timeline

  • 2026-08-14: disclosed
  • 2026-08-14: patched: Fixed in Security Center 6.9.0

References