Sceawere

Vulnerability Detail

CVE-2026-19629UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Tenable Security Center Privilege Escalation

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
3h ago
Vendor
Tenable, Inc.
Product
Security Center
Attack Type
CWE-863 (Incorrect Authorization)
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission on a single group to modify users belonging to other groups. This bypasses the intended access control restrictions and enables unauthorized cross-group user management.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-08-14T18:17:22.557Z",
  "pubdate": "2026-08-14T18:17:22.557Z",
  "executiveSummary": "A privilege escalation vulnerability has been identified in Tenable Security Center involving an authorization bypass within the user management subsystem. The flaw specifically impacts the access control enforcement mechanisms governing role-based permissions across distinct user groups. Specifically, an authenticated user assigned the 'Security Manager' role and endowed with 'manage user' permissions scoped strictly to a single, isolated group is capable of modifying user accounts belonging to entirely separate and unauthorized groups. This breakdown in security boundaries introduces significant risk implications, as lower-privileged administrators can effectively escalate their administrative control beyond their intended organizational domain, potentially compromising the integrity and security of the broader user directory. The exploitation of this vulnerability requires prior authentication with specific administrative privileges, relying on a flaw in server-side authorization checks rather than sophisticated memory corruption or external injection vectors. The impact centers on unauthorized cross-group user management, violating the principle of least privilege and multi-tenancy isolation within the affected software product.",
  "technicalDetails": "The root cause of this vulnerability lies in an inadequate authorization validation check within the Tenable Security Center backend application logic when processing administrative user modification requests. In a correctly implemented multi-tenant or scoped-permission architecture, the application should validate that the actor initiating a modification request possesses administrative scope over the targeted user entity's assigned group. However, the vulnerable component fails to adequately enforce this boundary for users holding the 'Security Manager' role who possess the 'manage user' permission within a constrained group context.\nThe attack flow proceeds as follows: First, the threat actor authenticates to the Tenable Security Center web interface using valid credentials associated with a 'Security Manager' role restricted by permissions to a single, designated user group. Second, the attacker initiates an administrative request to modify properties, attributes, or role assignments of a user account. By manipulating the target user identifier within the API request or parameter payload—specifically targeting a user entity belonging to a separate group outside the attacker's administrative domain—the attacker bypasses the intended boundary checks. Third, the backend application processes the modification request without verifying whether the requesting 'Security Manager' maintains administrative jurisdiction over the targeted user's group association. Consequently, the database transaction successfully updates the foreign user record.\nThe exploitation method relies on parameter manipulation and insecure direct object reference or missing function-level access control paradigms within the user management interface. The prerequisite conditions demand that the attacker already holds authenticated access with specific scoped privileges ('Security Manager' role with 'manage user' capability on a single group). The network exposure is dictated by the standard deployment interface of Tenable Security Center, typically accessible via HTTP/HTTPS services exposed to administrative users. The post-exploitation impact includes unauthorized modification of user accounts, potential takeover of administrative or higher-privileged accounts residing in other groups, and complete compromise of the logical access control segregation enforced within the platform."
}
CVE-2026-19629: Tenable Security Center Privilege Escalation (HIGH Severity, CVSS: 8.1) - Sceawere