Sceawere
Vulnerability Detail
CVE-2026-19626UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Tenable Security Center RCE Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.9
- Creation Date
- 1h ago
- Vendor
- Tenable, Inc.
- Product
- Security Center
- Attack Type
- CWE-95 Improper neutralization of directives in dynamically evaluated code ('eval injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted input that is later processed unsafely during server-side report rendering, resulting in arbitrary code execution with the privileges of the service account.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.9",
"pubDate": "2026-08-14T17:17:30.940Z",
"pubdate": "2026-08-14T17:17:30.940Z",
"executiveSummary": "An authenticated remote code execution vulnerability has been identified within the report generation functionality of Tenable Security Center.\nThe vulnerability allows an authenticated, non-administrative user to achieve arbitrary code execution on the underlying host operating system with the privileges of the executing service account.\nThe flaw stems from the insecure server-side processing of user-supplied input during the report rendering phase.\nSuccessful exploitation of this security defect compromises the confidentiality, integrity, and availability of the affected system and potentially grants the attacker a foothold within the internal network.\nThe attack requires authentication and the ability to interact with the report generation mechanisms of Tenable Security Center.",
"technicalDetails": "The vulnerability resides in the report generation subsystem of Tenable Security Center, specifically within the component responsible for processing and rendering server-side reports.\nThe root cause of the vulnerability is the unsafe handling and processing of specially crafted user-supplied input during the report rendering pipeline, leading to injection and subsequent execution of arbitrary code.\nAttack requirements mandate that the threat actor possesses valid user credentials capable of accessing the reporting interface, albeit without requiring administrative privileges.\nThe attack flow proceeds as follows: First, the authenticated, non-administrative user crafts a malicious payload designed to exploit the unsafe input processing within the report generation functionality. Second, the user submits this crafted input to Tenable Security Center via the standard reporting workflow. Third, the server-side application processes the payload unsafely during the rendering phase without proper sanitization, validation, or escaping. Finally, this improper handling triggers arbitrary code execution within the context of the service account running the affected service.\nThe post-exploitation impact includes the execution of arbitrary commands, potential lateral movement within the network, unauthorized access to sensitive vulnerability management data, and complete system compromise commensurate with the privileges of the service account."
}