CVE-2026-19679: Improper Input Validation
An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitization of uploaded filenames could contribute to a downstream command injection issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.9.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19679?
The severity of CVE-2026-19679 is rated as high with a score of 8.8.
What type of vulnerability is CVE-2026-19679?
CVE-2026-19679 is an input validation vulnerability specifically related to improper handling of uploaded filenames.
How can I mitigate the risks associated with CVE-2026-19679?
To mitigate CVE-2026-19679, implement proper sanitization measures for uploaded filenames to prevent command injection.
What is the potential impact of CVE-2026-19679?
The potential impact of CVE-2026-19679 includes downstream command injection vulnerabilities leading to unauthorized command execution.
Is CVE-2026-19679 present in all versions of Security Center?
The presence of CVE-2026-19679 may vary across versions of Security Center, so it is important to check your specific version for vulnerability details.