CVE-2026-19639: Improper Access Control
An improper access control vulnerability exists where an authenticated non-administrative application user could potentially view settings outside of their assigned scope.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Tenable Security Centerto a version that resolves this vulnerability.Fixed in 6.9.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19639?
The severity of CVE-2026-19639 is medium with a score of 4.3.
Who is affected by CVE-2026-19639?
CVE-2026-19639 affects authenticated non-administrative application users.
What type of vulnerability is CVE-2026-19639?
CVE-2026-19639 is classified as an improper access control vulnerability.
How can I mitigate CVE-2026-19639?
To mitigate CVE-2026-19639, ensure that access controls are properly enforced and restricted based on user roles.
What are the potential impacts of CVE-2026-19639?
The potential impact of CVE-2026-19639 is that unauthorized users may view application settings outside of their assigned permissions.