CVE-2026-19628
Last modified
CVE-2026-19628 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution on the underlying operating system when specific backend operations are triggered.. EPSS estimates a 2.00% chance of exploitation in the next 30 days.
Description
A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution on the underlying operating system when specific backend operations are triggered.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tenable | Security Center | < 6.9.0 |
References
- https://www.tenable.com/security/tns-2026-22Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-19628?
How severe is CVE-2026-19628?
How do I fix CVE-2026-19628?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-19617A flaw was found in libdm. A local attacker could craft a ma…5.5
- CVE-2026-19619GitLab has remediated an issue in GitLab CE/EE affecting all…4.7
- CVE-2026-1962A vulnerability has been found in WeKan up to 8.20. The impa…9.8
- CVE-2026-19624A flaw was found in NetworkManager-l2tp. The plugin writes a…7.8
- CVE-2026-19625When a Quarkus application has multiple endpoints secured by…5.3
- CVE-2026-19626A remote code execution vulnerability exists in Tenable Secu…9.9
- CVE-2026-19629A privilege escalation vulnerability exists in Tenable Secur…8.1
- CVE-2026-1963A vulnerability was found in WeKan up to 8.20. This affects …9.8
- CVE-2026-19631A SQL injection vulnerability exists in Security Center that…4.9
- CVE-2026-19632The TranslatePress – Translate Multilingual sites with AI Tr…9.8
- CVE-2026-19633PostgreSQL Anonymizer contains a vulnerability that allows u…8.8
- CVE-2026-19634PostgreSQL Anonymizer contains a SQL injection vulnerability…6.4
Are you affected by CVE-2026-19628?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
