Tenable Security Center
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Tenable Security Center.
By the Year
In 2026 there have been 19 vulnerabilities in Tenable Security Center with an average score of 7.9 out of ten. Last year, in 2025 Security Center had 1 security vulnerability published. That is, 18 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 3.59.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 19 | 7.89 |
| 2025 | 1 | 4.30 |
| 2024 | 5 | 5.93 |
It may take a day or so for new Security Center vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Tenable Security Center Security Vulnerabilities
Command injection in Windows Security Center service
CVE-2026-19682
9.9 - Critical
- August 14, 2026
A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating system with the privileges of the service account.
Shell injection
Authenticated Command Injection in Security Center File Upload
CVE-2026-19681
9.9 - Critical
- August 14, 2026
An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially crafted file, potentially resulting in arbitrary command execution on the underlying operating system.
Shell injection
SQL Injection in Tenable SecurityCenter DB
CVE-2026-19680
7.1 - High
- August 14, 2026
A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database.
SQL Injection
Security Center: Filename Validation Flaw Allows Cmd Injection
CVE-2026-19679
8.8 - High
- August 14, 2026
An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitization of uploaded filenames could contribute to a downstream command injection issue.
Shell injection
Improper Access Control (IAC) in Application Settings Access by Non-Admin Users
CVE-2026-19639
4.3 - Medium
- August 14, 2026
An improper access control vulnerability exists where an authenticated non-administrative application user could potentially view settings outside of their assigned scope.
Improper Validation of Specified Quantity in Input
Predictable CSRF Tokens Mitigated in Unknown Product
CVE-2026-19636
5.3 - Medium
- August 14, 2026
An issue was identified in which CSRF tokens were generated using a predictable method, potentially reducing their effectiveness as a security control. This has been addressed by improving the randomness and entropy of token generation.
Generation of Incorrect Security Tokens
Local Priv Esc via Config File in MS Security Center
CVE-2026-19635
8.8 - High
- August 14, 2026
A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific configuration file could achieve arbitrary code execution with elevated privileges, without requiring further user or victim interaction.
Shell injection
SQLi in Security Center Admin Auth can Execute Arbitrary SQL
CVE-2026-19631
4.9 - Medium
- August 14, 2026
A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbitrary SQL queries, potentially resulting in unauthorized access to sensitive data, including credentials.
SQL Injection
Privilege Escalation in Tenable Security Center Cross-Group User Mod
CVE-2026-19629
8.1 - High
- August 14, 2026
A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission on a single group to modify users belonging to other groups. This bypasses the intended access control restrictions and enables unauthorized cross-group user management.
AuthZ
Tenable Security Center Cmd Injection for Auth Admins
CVE-2026-19628
7.2 - High
- August 14, 2026
A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution on the underlying operating system when specific backend operations are triggered.
Shell injection
Remote Code Execution via report rendering in Tenable Security Center
CVE-2026-19626
9.9 - Critical
- August 14, 2026
A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted input that is later processed unsafely during server-side report rendering, resulting in arbitrary code execution with the privileges of the service account.
Eval Injection
Audit Upload Handler: Unsanitized Filenames Enable Cmd Injection
CVE-2026-64881
8.8 - High
- July 21, 2026
The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection when chained with a related vulnerability.
Shell injection
SQLi in Report Filter: Blind Injection via Unsanitized User Input
CVE-2026-64880
7.1 - High
- July 21, 2026
Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injection and unauthorized database read access.
SQL Injection
Command Injection via File Upload in Audit System
CVE-2026-64879
9.9 - Critical
- July 21, 2026
A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality.
Shell injection
Tenable Asset Filter RCE via Shell Metachar Escape
CVE-2026-64878
9.9 - Critical
- July 21, 2026
Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user via the Analysis REST endpoint.
Shell injection
Auth SQLi in Ticketing REST API - Sensitive Data Leak
CVE-2026-64877
8.4 - High
- July 21, 2026
An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.
Improper Input Validation
Improper Access Control in Unknown App Permits Authenticated Scope Escalation
CVE-2026-2698
6.5 - Medium
- February 23, 2026
An improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope.
Insecure Direct Object Reference / IDOR
IDOR in Qualys Security Center Enables Authenticated Remote Priv Escalation
CVE-2026-2697
6.3 - Medium
- February 23, 2026
An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges via the 'owner' parameter.
Insecure Direct Object Reference / IDOR
Auth Remote Cmd Injection in Tenable Security Center
CVE-2026-2630
8.8 - High
- February 17, 2026
A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the underlying server where Tenable Security Center is hosted.
Shell injection
Tenable Security Center <6.7.0 Improper Access Control (Authenticated)
CVE-2025-36636
4.3 - Medium
- October 08, 2025
In Tenable Security Center versions prior to 6.7.0, an improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope.
Authorization
Tenable Security Center: Improper Certificate Validation in SMTP Server Communication
CVE-2024-12174
- December 09, 2024
An Improper Certificate Validation vulnerability exists in Tenable Security Center where an authenticated, privileged attacker could intercept email messages sent from Security Center via a rogue SMTP server.
Tenable Security Center: Improper Privilege Management (CVE-2024-5759)
CVE-2024-5759
6.3 - Medium
- June 12, 2024
An improper privilege management vulnerability exists in Tenable Security Center where an authenticated, remote attacker could view unauthorized objects and launch scans without having the required privileges
Improper Privilege Management
Tenable Security Center Stored XSS in Scan Result Page
CVE-2024-1891
5.4 - Medium
- June 12, 2024
A stored cross site scripting vulnerability exists in Tenable Security Center where an authenticated, remote attacker could inject HTML code into a web application scan result page.
XSS
Security Center App: CLI Injection via Logging Params (CVE-2024-1367)
CVE-2024-1367
7.2 - High
- February 14, 2024
A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Logging parameters, which could lead to the execution of arbitrary code on the Security Center host.
Shell injection
Security Center Repo Params HTML Injection -> Redirection
CVE-2024-1471
4.8 - Medium
- February 14, 2024
An HTML injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Repository parameters, which could lead to HTML redirection attacks.
XSS
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Tenable Security Center or by Tenable? Click the Watch button to subscribe.