CVE-2026-19628: Remote Code Execution
A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution on the underlying operating system when specific backend operations are triggered.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Tenable Security Centerto a version that resolves this vulnerability.Fixed in 6.9.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19628?
The severity of CVE-2026-19628 is rated high, with a score of 7.2.
What is CVE-2026-19628 related to?
CVE-2026-19628 is related to a command injection vulnerability in Tenable Security Center.
How do I fix CVE-2026-19628?
To fix CVE-2026-19628, update the Tenable Security Center to the latest version provided by Tenable.
Who is affected by CVE-2026-19628?
Authenticated administrators of Tenable Security Center are affected by CVE-2026-19628.
What could happen if CVE-2026-19628 is exploited?
If exploited, CVE-2026-19628 could allow an attacker to execute arbitrary commands on the underlying operating system.