Sceawere

Vulnerability Detail

CVE-2026-19628UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Tenable Security Center Command Injection

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
1h ago
Vendor
Tenable, Inc.
Product
Security Center
Attack Type
CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution on the underlying operating system when specific backend operations are triggered.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-08-14T17:17:31.110Z",
  "pubdate": "2026-08-14T17:17:31.110Z",
  "executiveSummary": "An authenticated command injection vulnerability has been identified in Tenable Security Center.\nThe vulnerability allows an authenticated administrator to modify application configuration values in a manner that leads to arbitrary command execution on the underlying operating system.\nThe primary impact of this flaw is full system compromise, as successful exploitation enables attackers to execute arbitrary system-level commands with the privileges of the underlying application service or root, depending on the service configuration.\nThe affected product is Tenable Security Center.\nThe risk implications are severe, as an attacker with administrative access can bypass application boundaries to interact directly with the underlying operating system, potentially leading to data exfiltration, lateral movement, or complete infrastructure takeover.\nExploitation requires authenticated administrative access to the Tenable Security Center application and the ability to modify specific application configuration values that interface with backend operations.\nOnce the malicious configuration is submitted, the execution is triggered when specific backend operations or system routines are subsequently invoked by the application.",
  "technicalDetails": "The vulnerability is a command injection flaw residing within the application configuration management functionality of Tenable Security Center.\nThe root cause stems from insecure handling and insufficient sanitization of administrative input supplied to application configuration parameters.\nWhen specific backend operations or system-level routines are triggered, these unsanitized configuration values are improperly passed to the underlying operating system shell or command interpreter.\nThe attack vector requires the adversary to authenticate to the Tenable Security Center administrative interface and navigate to the vulnerable configuration settings.\nThe attacker modifies specific configuration parameters to include malicious shell metacharacters or command sequences designed to break out of the intended application logic and execute arbitrary system commands.\nUpon saving the malicious configuration, the attacker triggers the specific backend operations associated with the modified parameters.\nThe application reads the tainted configuration values and incorporates them directly into execution strings passed to the operating system shell.\nThis results in the evaluation and execution of the injected payload by the underlying operating system.\nPrivilege requirements include authenticated administrative access within Tenable Security Center.\nThe network exposure depends on the accessibility of the Tenable Security Center administrative web interface.\nThe post-exploitation impact includes arbitrary command execution, allowing the threat actor to read sensitive files, install persistent backdoors, pivot to other internal network segments, or disrupt core monitoring and security operations managed by Tenable Security Center."
}
CVE-2026-19628: Tenable Security Center Command Injection (HIGH Severity, CVSS: 7.2) - Sceawere