CVE-2026-19682: Command Injection
A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating system with the privileges of the service account.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Tenable Security Centerto a version that resolves this vulnerability.Fixed in 6.9.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19682?
CVE-2026-19682 has a critical severity rating of 9.9.
What type of vulnerability is CVE-2026-19682?
CVE-2026-19682 is classified as a command injection vulnerability.
How do I fix CVE-2026-19682?
To mitigate CVE-2026-19682, update Security Center to the latest version that addresses this vulnerability.
What could an attacker do with CVE-2026-19682?
An unauthenticated attacker could exploit CVE-2026-19682 to execute arbitrary commands on the system with the privileges of the service account.
Who is affected by CVE-2026-19682?
Any users of Security Center that have not patched or updated against CVE-2026-19682 are at risk.