Executive brief
Tenable Security Center, a vulnerability management platform used by enterprises to discover and assess security risks, contains an OS command injection flaw. A remote attacker with low-level credentials can execute arbitrary system commands with service account privileges, potentially allowing full system compromise, data theft, and lateral movement throughout the organization.
Technical details
The vulnerability is an OS command injection flaw in Tenable Security Center that allows remote command execution. While the advisory summary states the issue can be exploited by an unauthenticated attacker, the Tenable security advisory indicates the actual precondition requires authentication (PR:L - low privilege). The attack vector is network-based with low complexity. Successful exploitation allows an attacker to execute arbitrary commands on the underlying operating system with the privileges of the Security Center service account, achieving complete system compromise including confidentiality, integrity, and availability impact. Tenable has released Security Center version 6.9.0 as a patch.
Affected products
- Tenable Security Center before 6.9.0
Timeline
- 2026-08-14: disclosed