Security Center Tenable Security Center

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Tenable Security Center.

By the Year

In 2026 there have been 19 vulnerabilities in Tenable Security Center with an average score of 7.9 out of ten. Last year, in 2025 Security Center had 1 security vulnerability published. That is, 18 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 3.59.

Year Vulnerabilities Average Score
2026 19 7.89
2025 1 4.30
2024 5 5.93

It may take a day or so for new Security Center vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Tenable Security Center Security Vulnerabilities

Command injection in Windows Security Center service
CVE-2026-19682 9.9 - Critical - August 14, 2026

A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating system with the privileges of the service account.

Shell injection

Authenticated Command Injection in Security Center File Upload
CVE-2026-19681 9.9 - Critical - August 14, 2026

An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially crafted file, potentially resulting in arbitrary command execution on the underlying operating system.

Shell injection

SQL Injection in Tenable SecurityCenter DB
CVE-2026-19680 7.1 - High - August 14, 2026

A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database.

SQL Injection

Security Center: Filename Validation Flaw Allows Cmd Injection
CVE-2026-19679 8.8 - High - August 14, 2026

An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitization of uploaded filenames could contribute to a downstream command injection issue.

Shell injection

Improper Access Control (IAC) in Application Settings Access by Non-Admin Users
CVE-2026-19639 4.3 - Medium - August 14, 2026

An improper access control vulnerability exists where an authenticated non-administrative application user could potentially view settings outside of their assigned scope.

Improper Validation of Specified Quantity in Input

Predictable CSRF Tokens Mitigated in Unknown Product
CVE-2026-19636 5.3 - Medium - August 14, 2026

An issue was identified in which CSRF tokens were generated using a predictable method, potentially reducing their effectiveness as a security control. This has been addressed by improving the randomness and entropy of token generation.

Generation of Incorrect Security Tokens

Local Priv Esc via Config File in MS Security Center
CVE-2026-19635 8.8 - High - August 14, 2026

A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific configuration file could achieve arbitrary code execution with elevated privileges, without requiring further user or victim interaction.

Shell injection

SQLi in Security Center Admin Auth can Execute Arbitrary SQL
CVE-2026-19631 4.9 - Medium - August 14, 2026

A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbitrary SQL queries, potentially resulting in unauthorized access to sensitive data, including credentials.

SQL Injection

Privilege Escalation in Tenable Security Center Cross-Group User Mod
CVE-2026-19629 8.1 - High - August 14, 2026

A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission on a single group to modify users belonging to other groups. This bypasses the intended access control restrictions and enables unauthorized cross-group user management.

AuthZ

Tenable Security Center Cmd Injection for Auth Admins
CVE-2026-19628 7.2 - High - August 14, 2026

A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution on the underlying operating system when specific backend operations are triggered.

Shell injection

Remote Code Execution via report rendering in Tenable Security Center
CVE-2026-19626 9.9 - Critical - August 14, 2026

A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted input that is later processed unsafely during server-side report rendering, resulting in arbitrary code execution with the privileges of the service account.

Eval Injection

Audit Upload Handler: Unsanitized Filenames Enable Cmd Injection
CVE-2026-64881 8.8 - High - July 21, 2026

The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection when chained with a related vulnerability.

Shell injection

SQLi in Report Filter: Blind Injection via Unsanitized User Input
CVE-2026-64880 7.1 - High - July 21, 2026

Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injection and unauthorized database read access.

SQL Injection

Command Injection via File Upload in Audit System
CVE-2026-64879 9.9 - Critical - July 21, 2026

A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality.

Shell injection

Tenable Asset Filter RCE via Shell Metachar Escape
CVE-2026-64878 9.9 - Critical - July 21, 2026

Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user via the Analysis REST endpoint.

Shell injection

Auth SQLi in Ticketing REST API - Sensitive Data Leak
CVE-2026-64877 8.4 - High - July 21, 2026

An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.

Improper Input Validation

Improper Access Control in Unknown App Permits Authenticated Scope Escalation
CVE-2026-2698 6.5 - Medium - February 23, 2026

An improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope.

Insecure Direct Object Reference / IDOR

IDOR in Qualys Security Center Enables Authenticated Remote Priv Escalation
CVE-2026-2697 6.3 - Medium - February 23, 2026

An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges via the 'owner' parameter.

Insecure Direct Object Reference / IDOR

Auth Remote Cmd Injection in Tenable Security Center
CVE-2026-2630 8.8 - High - February 17, 2026

A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the underlying server where Tenable Security Center is hosted.

Shell injection

Tenable Security Center <6.7.0 Improper Access Control (Authenticated)
CVE-2025-36636 4.3 - Medium - October 08, 2025

In Tenable Security Center versions prior to 6.7.0, an improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope.

Authorization

Tenable Security Center: Improper Certificate Validation in SMTP Server Communication
CVE-2024-12174 - December 09, 2024

An Improper Certificate Validation vulnerability exists in Tenable Security Center where an authenticated, privileged attacker could intercept email messages sent from Security Center via a rogue SMTP server.

Tenable Security Center: Improper Privilege Management (CVE-2024-5759)
CVE-2024-5759 6.3 - Medium - June 12, 2024

An improper privilege management vulnerability exists in Tenable Security Center where an authenticated, remote attacker could view unauthorized objects and launch scans without having the required privileges

Improper Privilege Management

Tenable Security Center Stored XSS in Scan Result Page
CVE-2024-1891 5.4 - Medium - June 12, 2024

A stored cross site scripting vulnerability exists in Tenable Security Center where an authenticated, remote attacker could inject HTML code into a web application scan result page.

XSS

Security Center App: CLI Injection via Logging Params (CVE-2024-1367)
CVE-2024-1367 7.2 - High - February 14, 2024

A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Logging parameters, which could lead to the execution of arbitrary code on the Security Center host.

Shell injection

Security Center Repo Params HTML Injection -> Redirection
CVE-2024-1471 4.8 - Medium - February 14, 2024

An HTML injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Repository parameters, which could lead to HTML redirection attacks.

XSS

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Tenable Security Center or by Tenable? Click the Watch button to subscribe.

Tenable
Vendor

subscribe