Tenable
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Tenable product.
RSS Feeds for Tenable security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Tenable products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Tenable Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 31 vulnerabilities in Tenable with an average score of 7.7 out of ten. Last year, in 2025 Tenable had 7 security vulnerabilities published. That is, 24 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.93.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 31 | 7.66 |
| 2025 | 7 | 6.73 |
| 2024 | 14 | 5.86 |
| 2023 | 16 | 6.99 |
| 2022 | 19 | 8.23 |
| 2021 | 25 | 7.31 |
| 2020 | 22 | 6.33 |
| 2019 | 20 | 6.53 |
| 2018 | 8 | 6.17 |
It may take a day or so for new Tenable vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Tenable Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-19682 | Aug 14, 2026 |
Command injection in Windows Security Center serviceA command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating system with the privileges of the service account. |
|
| CVE-2026-19681 | Aug 14, 2026 |
Authenticated Command Injection in Security Center File UploadAn authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially crafted file, potentially resulting in arbitrary command execution on the underlying operating system. |
|
| CVE-2026-19680 | Aug 14, 2026 |
SQL Injection in Tenable SecurityCenter DBA SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database. |
|
| CVE-2026-19679 | Aug 14, 2026 |
Security Center: Filename Validation Flaw Allows Cmd InjectionAn input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitization of uploaded filenames could contribute to a downstream command injection issue. |
|
| CVE-2026-19639 | Aug 14, 2026 |
Improper Access Control (IAC) in Application Settings Access by Non-Admin UsersAn improper access control vulnerability exists where an authenticated non-administrative application user could potentially view settings outside of their assigned scope. |
|
| CVE-2026-19636 | Aug 14, 2026 |
Predictable CSRF Tokens Mitigated in Unknown ProductAn issue was identified in which CSRF tokens were generated using a predictable method, potentially reducing their effectiveness as a security control. This has been addressed by improving the randomness and entropy of token generation. |
|
| CVE-2026-19635 | Aug 14, 2026 |
Local Priv Esc via Config File in MS Security CenterA local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific configuration file could achieve arbitrary code execution with elevated privileges, without requiring further user or victim interaction. |
|
| CVE-2026-19631 | Aug 14, 2026 |
SQLi in Security Center Admin Auth can Execute Arbitrary SQLA SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbitrary SQL queries, potentially resulting in unauthorized access to sensitive data, including credentials. |
|
| CVE-2026-19629 | Aug 14, 2026 |
Privilege Escalation in Tenable Security Center Cross-Group User ModA privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission on a single group to modify users belonging to other groups. This bypasses the intended access control restrictions and enables unauthorized cross-group user management. |
|
| CVE-2026-19628 | Aug 14, 2026 |
Tenable Security Center Cmd Injection for Auth AdminsA command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution on the underlying operating system when specific backend operations are triggered. |
|
| CVE-2026-19626 | Aug 14, 2026 |
Remote Code Execution via report rendering in Tenable Security CenterA remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted input that is later processed unsafely during server-side report rendering, resulting in arbitrary code execution with the privileges of the service account. |
|
| CVE-2026-18667 | Aug 03, 2026 |
Remote Code Execution via Elevated Privileges in Tenable Sensor ProxyA vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an operator to connect the sensor to an attacker-controlled host. |
|
| CVE-2026-64881 | Jul 21, 2026 |
Audit Upload Handler: Unsanitized Filenames Enable Cmd InjectionThe audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection when chained with a related vulnerability. |
|
| CVE-2026-64880 | Jul 21, 2026 |
SQLi in Report Filter: Blind Injection via Unsanitized User InputUnsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injection and unauthorized database read access. |
|
| CVE-2026-64879 | Jul 21, 2026 |
Command Injection via File Upload in Audit SystemA filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality. |
|
| CVE-2026-64878 | Jul 21, 2026 |
Tenable Asset Filter RCE via Shell Metachar EscapeUnvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user via the Analysis REST endpoint. |
|
| CVE-2026-64877 | Jul 21, 2026 |
Auth SQLi in Ticketing REST API - Sensitive Data LeakAn authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database. |
|
| CVE-2026-15265 | Jul 14, 2026 |
Tenable Agent <11.2 PT writes arbitrary filesA path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intended plugin directory, potentially leading to remote code execution. |
|
| CVE-2026-57588 | Jun 25, 2026 |
SQLi via Malicious Scan File in NessusA SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by a privileged user, injects malicious SQL into the scan results database, potentially enabling exfiltration of scan-result data. |
|
| CVE-2026-57587 | Jun 25, 2026 |
SQL Injection in Nessus via Reverse DNSA SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a scanned host to inject malicious SQL into the scan results database, potentially enabling exfiltration of scan-result data. |
|
| CVE-2026-13007 | Jun 23, 2026 |
Unauthenticated API & Cache-Control Leak in Tenable IdentityTenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive application configuration data including cleartext LDAP credentials, SAML configuration, user accounts, and directory settings to unauthenticated remote attackers. Affected responses are served with Cache-Control: public headers and without Vary: Cookie, allowing reverse proxies and CDNs to cache and serve sensitive data to unauthenticated users even after authentication is applied. |
|
| CVE-2026-47358 | May 19, 2026 |
Terrascan <=1.18.3 SSRF via URL resolution in server modeTerrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC templates when running in server mode. When Terrascan parses uploaded ARM templates or CloudFormation templates, it resolves external URLs referenced within those templates via hashicorp/go-getter with all default detectors enabled, including FileDetector. An unauthenticated remote attacker can upload an ARM template containing a templateLink.uri or parametersLink.uri field, or a CloudFormation template containing an AWS::CloudFormation::Stack TemplateURL field, pointing to an attacker-controlled URL. Terrascan will fetch the attacker-controlled URL server-side. Unlike SSRF via the remote scan endpoint, file:// URLs are directly usable without requiring an X-Terraform-Get redirect, enabling local file read. This affects deployments running terrascan in server mode (terrascan server), which binds to 0.0.0.0 with no authentication. Note: Terrascan was archived in August 2023 and no patch will be released. |
|
| CVE-2026-47357 | May 19, 2026 |
Terrascan SSRF: remote_url (v1.18.3+) in Server ModeTerrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote directory scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/remote/dir/scan) when running in server mode. An unauthenticated remote attacker can supply an attacker-controlled HTTP URL as remote_url with remote_type set to "http". The URL is passed directly to hashicorp/go-getter (v1.7.5) without validation. Go-getter's HttpGetter supports the X-Terraform-Get response header, allowing the attacker's server to redirect the download to a file:// URL, enabling local file read. Additionally, HttpGetter has Netrc set to true, causing it to read ~/.netrc and send stored credentials to attacker-controlled hostnames. This affects deployments running terrascan in server mode (terrascan server), which binds to 0.0.0.0 with no authentication. Note: Terrascan was archived in August 2023 and no patch will be released. |
|
| CVE-2026-47356 | May 19, 2026 |
Terrascan v1.18.3 and earlier SSRF via webhook_url in file scan endpointTerrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the file scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/local/file/scan) when running in server mode. An unauthenticated remote attacker can supply an arbitrary URL as the webhook_url multipart form parameter. After scanning the uploaded file, Terrascan sends an HTTP POST request to the attacker-controlled URL containing the full scan results as a JSON body, with the attacker-supplied webhook_token forwarded as a Bearer token in the Authorization header. The retryable HTTP client retries up to 10 times on failure. This affects deployments running terrascan in server mode (terrascan server), which binds to 0.0.0.0 with no authentication. Note: Terrascan was archived in August 2023 and no patch will be released. |
|
| CVE-2026-33694 | Apr 23, 2026 |
Windows Junction Bypass Enables SYSTEM Privilege File Deletion (CVE-2026-33694)This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges. As a result, this condition potentially facilitates arbitrary code execution, whereby an attacker may exploit the vulnerability to execute malicious code with elevated SYSTEM privileges. |
|
| CVE-2026-4433 | Mar 24, 2026 |
SSH Misconfig in Tenable OT Exposes Service Info via GatewayPortsAn SSH misconfigurations exists in Tenable OT that led to the potential exfiltration of socket, port, and service information via the ostunnel user and GatewayPorts. This could be used to potentially glean information about the underlying system and give an attacker information that could be used to attempt to compromise the host. |
|
| CVE-2026-2698 | Feb 23, 2026 |
Improper Access Control in Unknown App Permits Authenticated Scope EscalationAn improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope. |
|
| CVE-2026-2697 | Feb 23, 2026 |
IDOR in Qualys Security Center Enables Authenticated Remote Priv EscalationAn Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges via the 'owner' parameter. |
|
| CVE-2026-2630 | Feb 17, 2026 |
Auth Remote Cmd Injection in Tenable Security CenterA Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the underlying server where Tenable Security Center is hosted. |
|
| CVE-2026-2026 | Feb 13, 2026 |
Nessus Agent Weak File Perms Allow Unauthorized Access on WindowsA vulnerability has been identified where weak file permissions in the Nessus Agent directory on Windows hosts could allow unauthorized access, potentially permitting Denial of Service (DoS) attacks. |
|
| CVE-2025-36640 | Jan 13, 2026 |
Privilege Escalation in Nessus Agent Tray App Windows install/uninstallA vulnerability has been identified in the installation/uninstallation of the Nessus Agent Tray App on Windows Hosts which could lead to escalation of privileges. |
|
| CVE-2025-36636 | Oct 08, 2025 |
Tenable Security Center <6.7.0 Improper Access Control (Authenticated)In Tenable Security Center versions prior to 6.7.0, an improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope. |
|
| CVE-2025-36630 | Jul 02, 2025 |
Tenable Nessus <10.8.5 - Arbitrary Local File Overwrite via Log (SYSTEM PrivEsc)In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege. |
|
| CVE-2025-24917 | May 23, 2025 |
Tenable Network Monitor <6.5.1 LPE via local dir staging (Windows)In Tenable Network Monitor versions prior to 6.5.1 on a Windows host, it was found that a non-administrative user could stage files in a local directory to run arbitrary code with SYSTEM privileges, potentially leading to local privilege escalation. |
|
| CVE-2025-24916 | May 23, 2025 |
Tenable Network Monitor <6.5.1 LPE via insecure dirs in custom installWhen installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions prior to 6.5.1 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location. |
|
| CVE-2025-36625 | Apr 18, 2025 |
Nessus <=10.8.3 Log Entry Manipulation via HTTPIn Nessus versions prior to 10.8.4, a non-authenticated attacker could alter Nessus logging entries by manipulating http requests to the application. |
|
| CVE-2025-24914 | Apr 18, 2025 |
Nessus<10.8.4 Windows SUBDIR insecure perms => LPEWhen installing Nessus to a non-default location on a Windows host, Nessus versions prior to 10.8.4 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location. - CVE-2025-24914 |
|
| CVE-2025-24915 | Mar 21, 2025 |
LPE in Nessus Agent <10.8.3 on Windows via insecure non-default installWhen installing Nessus Agent to a non-default location on a Windows host, Nessus Agent versions prior to 10.8.3 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location. |
|
| CVE-2024-12174 | Dec 09, 2024 |
Tenable Security Center: Improper Certificate Validation in SMTP Server CommunicationAn Improper Certificate Validation vulnerability exists in Tenable Security Center where an authenticated, privileged attacker could intercept email messages sent from Security Center via a rogue SMTP server. |
|
| CVE-2024-9158 | Sep 30, 2024 |
Nessus NNM Stored XSS via CLI InjectionA stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local attacker could inject arbitrary code into the NNM UI via the local CLI. |
|
| CVE-2024-1891 | Jun 12, 2024 |
Tenable Security Center Stored XSS in Scan Result PageA stored cross site scripting vulnerability exists in Tenable Security Center where an authenticated, remote attacker could inject HTML code into a web application scan result page. |
|
| CVE-2024-5759 | Jun 12, 2024 |
Tenable Security Center: Improper Privilege Management (CVE-2024-5759)An improper privilege management vulnerability exists in Tenable Security Center where an authenticated, remote attacker could view unauthorized objects and launch scans without having the required privileges |
|
| CVE-2024-3292 | May 17, 2024 |
Local Authenticated Race Condition in Windows Nessus Agent Allows Arbitrary Code ExecutionA race condition vulnerability exists where an authenticated, local attacker on a Windows Nessus Agent host could modify installation parameters at installation time, which could lead to the execution of arbitrary code on the Nessus host. - CVE-2024-3292 |
|
| CVE-2024-3289 | May 17, 2024 |
Nessus Windows LPE via insecure subdir permissions before 10.7.3When installing Nessus to a directory outside of the default location on a Windows host, Nessus versions prior to 10.7.3 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location. |
|
| CVE-2024-3290 | May 17, 2024 |
Nessus Windows Auth Local Race Condition Enables Arbitrary Code ExecA race condition vulnerability exists where an authenticated, local attacker on a Windows Nessus host could modify installation parameters at installation time, which could lead to the execution of arbitrary code on the Nessus host |
|
| CVE-2024-3291 | May 17, 2024 |
Nessus Agent <10.6.4 Windows LPE via insecure install path permsWhen installing Nessus Agent to a directory outside of the default location on a Windows host, Nessus Agent versions prior to 10.6.4 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location. |
|
| CVE-2024-2390 | Mar 18, 2024 |
Priv Esc via Nessus Plugin CVE-2024-2390As a part of Tenables vulnerability disclosure program, a vulnerability in a Nessus plugin was identified and reported. This vulnerability could allow a malicious actor with sufficient permissions on a scan target to place a binary in a specific filesystem location, and abuse the impacted plugin in order to escalate privileges. |
|
| CVE-2024-1683 | Feb 23, 2024 |
DLL Injection in TIE Secure Relay Host allows local file overwriteA DLL injection vulnerability exists where an authenticated, low-privileged local attacker could modify application files on the TIE Secure Relay host, which could allow for overriding of the configuration and running of new Secure Relay services. |
|
| CVE-2024-1367 | Feb 14, 2024 |
Security Center App: CLI Injection via Logging Params (CVE-2024-1367)A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Logging parameters, which could lead to the execution of arbitrary code on the Security Center host. |
|
| CVE-2024-1471 | Feb 14, 2024 |
Security Center Repo Params HTML Injection -> RedirectionAn HTML injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Repository parameters, which could lead to HTML redirection attacks. |
|