CVE-2026-19626: Remote Code Execution
A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted input that is later processed unsafely during server-side report rendering, resulting in arbitrary code execution with the privileges of the service account.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Tenable Security Centerto a version that resolves this vulnerability.Fixed in 6.9.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19626?
CVE-2026-19626 has a critical severity rating of 9.9.
How do I fix CVE-2026-19626?
To fix CVE-2026-19626, update Tenable Security Center to the latest patched version provided by Tenable.
What type of vulnerability is CVE-2026-19626?
CVE-2026-19626 is a remote code execution vulnerability.
Who can exploit CVE-2026-19626?
An authenticated, non-administrative user can exploit CVE-2026-19626.
What could happen if CVE-2026-19626 is successfully exploited?
Successful exploitation of CVE-2026-19626 could allow an attacker to execute arbitrary code on the server.