Tenable
- 13
- vulnérabilités suivies
- 5
- critiques
- 14 août 2026
- dernière publication
cve
Veille des vulnérabilités
identifiantvulnérabilitésévéritépublié
CVE-2026-19626A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted input that is later processed unsafely during server-side report rendering, resulting in arbitrary code execution with the privileges of the service account.Tenable Security Center Critique CVSS 9.9 CVE-2026-19628A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution on the underlying operating system when specific backend operations are triggered.Tenable Security Center Élevée CVSS 7.2 CVE-2026-19629A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission on a single group to modify users belonging to other groups. This bypasses the intended access control restrictions and enables unauthorized cross-group user management.Tenable Security Center Élevée CVSS 8.1 CVE-2026-19635A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific configuration file could achieve arbitrary code execution with elevated privileges, without requiring further user or victim interaction.Tenable Security Center Élevée CVSS 8.8 CVE-2026-19679An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitization of uploaded filenames could contribute to a downstream command injection issue.Tenable Security Center Élevée CVSS 8.8 CVE-2026-19680A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database.Tenable Security Center Élevée CVSS 7.1 CVE-2026-19681An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially crafted file, potentially resulting in arbitrary command execution on the underlying operating system.Tenable Security Center Critique CVSS 9.9 CVE-2026-19682A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating system with the privileges of the service account.Tenable Security Center Critique CVSS 9.9 CVE-2026-64877An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.Tenable Security Center Élevée CVSS 8.4 CVE-2026-64878Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user via the Analysis REST endpoint.Tenable Security Center Critique CVSS 9.9 CVE-2026-64879A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality.Tenable Security Center Critique CVSS 9.9 CVE-2026-64880Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injection and unauthorized database read access.Tenable Security Center Élevée CVSS 7.1 CVE-2026-64881The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection when chained with a related vulnerability.Tenable Security Center Élevée CVSS 8.8