Executive brief
Tenable Security Center, a vulnerability management platform used to scan and assess network security, contains a critical command injection flaw in its file upload functionality. An authenticated attacker can upload a specially crafted file to execute arbitrary commands on the server, potentially gaining full control of the system and compromising all assets managed by the platform.
Technical details
This is an authenticated OS command injection vulnerability (CVE-2026-19681) in Tenable Security Center's file upload processing component. The vulnerability requires valid authentication credentials but has a network attack vector with no user interaction needed. An attacker can craft a malicious file that, when uploaded, triggers unsanitized command execution on the underlying operating system. The attack achieves complete confidentiality, integrity, and availability compromise across the Security Center system. Tenable released version 6.9.0 to patch this and multiple related command injection flaws.
Affected products
- Tenable Security Center below 6.9.0
Timeline
- 2026-08-14: disclosed
- 2026-08-14: patched: Fixed in Security Center 6.9.0