CVE-2026-19682
- EPSS 1.97%
- Veröffentlicht 14.08.2026 17:51:55
- Zuletzt bearbeitet 19.08.2026 16:46:51
A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating system with the privileges of the service account.
CVE-2026-19681
- EPSS 2.29%
- Veröffentlicht 14.08.2026 17:45:37
- Zuletzt bearbeitet 19.08.2026 16:47:25
An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially crafted file, potentially resulting in arbitrary command execution on the unde...
CVE-2026-19680
- EPSS 0.32%
- Veröffentlicht 14.08.2026 17:39:21
- Zuletzt bearbeitet 19.08.2026 16:52:00
A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database.
CVE-2026-19679
- EPSS 1.6%
- Veröffentlicht 14.08.2026 17:35:46
- Zuletzt bearbeitet 19.08.2026 17:10:07
An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitization of uploaded filenames could contribute to a downstream command injection issue.
CVE-2026-19639
- EPSS 0.3%
- Veröffentlicht 14.08.2026 17:28:49
- Zuletzt bearbeitet 19.08.2026 17:02:55
An improper access control vulnerability exists where an authenticated non-administrative application user could potentially view settings outside of their assigned scope.
- EPSS 0.26%
- Veröffentlicht 14.08.2026 17:24:21
- Zuletzt bearbeitet 19.08.2026 17:03:24
An issue was identified in which CSRF tokens were generated using a predictable method, potentially reducing their effectiveness as a security control. This has been addressed by improving the randomness and entropy of token generation.
CVE-2026-19635
- EPSS 0.19%
- Veröffentlicht 14.08.2026 17:12:52
- Zuletzt bearbeitet 19.08.2026 17:04:02
A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific configuration file could achieve arbitrary code execution with elevated privileges, without requiring further user or victim interaction...
CVE-2026-19631
- EPSS 0.39%
- Veröffentlicht 14.08.2026 17:08:53
- Zuletzt bearbeitet 19.08.2026 17:10:37
A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbitrary SQL queries, potentially resulting in unauthorized access to sensitive data, including credentials.
CVE-2026-19629
- EPSS 0.39%
- Veröffentlicht 14.08.2026 17:04:19
- Zuletzt bearbeitet 19.08.2026 17:10:58
A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission on a single group to modify users belonging to other groups. This bypasses the intended access control...
CVE-2026-19628
- EPSS 2.1%
- Veröffentlicht 14.08.2026 17:00:01
- Zuletzt bearbeitet 19.08.2026 17:12:12
A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution on the underlying operating system when specific backend operatio...