CVE-2026-19631: SQL Injection
A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbitrary SQL queries, potentially resulting in unauthorized access to sensitive data, including credentials.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Tenable Security Centerto a version that resolves this vulnerability.Fixed in 6.9.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19631?
The severity of CVE-2026-19631 is classified as medium with a CVSS score of 4.9.
How do I fix CVE-2026-19631?
To fix CVE-2026-19631, update Security Center to the latest patched version provided by the vendor.
Who is affected by CVE-2026-19631?
CVE-2026-19631 affects authenticated administrators using Security Center.
What kind of attack does CVE-2026-19631 enable?
CVE-2026-19631 enables an authenticated administrator to perform SQL injection attacks that could result in unauthorized access to sensitive data.
What are the potential impacts of CVE-2026-19631?
The potential impacts of CVE-2026-19631 include unauthorized access to sensitive data, including user credentials.