Junglewise Threat Intelligence

CVE-2026-19681: Tenable Security Center OS command injection in file upload

CVE-2026-19681 · Severity: critical · CVSS 9.9 · Published 2026-08-14

Vendors: Tenable.

Executive brief

Tenable Security Center, a vulnerability management platform used to scan and assess network security, contains a critical command injection flaw in its file upload functionality. An authenticated attacker can upload a specially crafted file to execute arbitrary commands on the server, potentially gaining full control of the system and compromising all assets managed by the platform.

Technical details

This is an authenticated OS command injection vulnerability (CVE-2026-19681) in Tenable Security Center's file upload processing component. The vulnerability requires valid authentication credentials but has a network attack vector with no user interaction needed. An attacker can craft a malicious file that, when uploaded, triggers unsanitized command execution on the underlying operating system. The attack achieves complete confidentiality, integrity, and availability compromise across the Security Center system. Tenable released version 6.9.0 to patch this and multiple related command injection flaws.

Affected products

  • Tenable Security Center below 6.9.0

Timeline

  • 2026-08-14: disclosed
  • 2026-08-14: patched: Fixed in Security Center 6.9.0

References