CVE-2026-19631
MEDIUMCVSS 4.9/10EPSS 0.39%
Last modified
CVE-2026-19631 is a medium-severity vulnerability rated 4.9/10 on the CVSS scale. A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbitrary SQL queries, potentially resulting in unauthorized access to sensitive data, including credentials.. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbitrary SQL queries, potentially resulting in unauthorized access to sensitive data, including credentials.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tenable | Security Center | < 6.9.0 |
References
- https://www.tenable.com/security/tns-2026-22Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-19631?
A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbitrary SQL queries, potentially resulting in unauthorized access to sensitive data, including credentials.
How severe is CVE-2026-19631?
CVE-2026-19631 has a CVSS score of 4.9/10 (MEDIUM severity). The EPSS model estimates a 0.39% probability of exploitation in the next 30 days.
How do I fix CVE-2026-19631?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-19624A flaw was found in NetworkManager-l2tp. The plugin writes a…7.8
- CVE-2026-19625When a Quarkus application has multiple endpoints secured by…5.3
- CVE-2026-19626A remote code execution vulnerability exists in Tenable Secu…9.9
- CVE-2026-19628A command injection vulnerability exists in Tenable Security…7.2
- CVE-2026-19629A privilege escalation vulnerability exists in Tenable Secur…8.1
- CVE-2026-1963A vulnerability was found in WeKan up to 8.20. This affects …9.8
- CVE-2026-19632The TranslatePress – Translate Multilingual sites with AI Tr…9.8
- CVE-2026-19633PostgreSQL Anonymizer contains a vulnerability that allows u…8.8
- CVE-2026-19634PostgreSQL Anonymizer contains a SQL injection vulnerability…6.4
- CVE-2026-19635A local privilege escalation vulnerability exists in Securit…8.8
- CVE-2026-19636An issue was identified in which CSRF tokens were generated …5.3
- CVE-2026-19639An improper access control vulnerability exists where an aut…4.3
Are you affected by CVE-2026-19631?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
