CVE-2026-19635

medium

Description

Security Center leverages third-party software to help provide underlying functionality. Several of the third-party components (curl, underscoreJS) were found to contain vulnerabilities, and updated versions have been made available by the providers. Out of caution and in line with best practice, Tenable has opted to upgrade these libraries to address the potential impact of the issues. Security Center 6.9.0 updates the following components:curl to version 8.20underscoreJS to version 1.13.8Additionally, several vulnerabilities were reported to Tenable and addressed within this update. Please see the full list of resolved issues below.ComponentCVE ID Severity CVSS v3 BaseCVSS v3 Temporal CVSS v3 VectorSecurity Center - Improper Access ControlCVE-2026-19639Medium4.33.9AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:CSecurity Center - OS Command InjectionCVE-2026-19682Critical9.09.0AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HSecurity Center - OS Command InjectionCVE-2026-19681Critical9.98.9AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:CSecurity Center - SQL InjectionCVE-2026-19680High7.16.4AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N/E:P/RL:O/RC:CSecurity Center - OS Command InjectionCVE-2026-19679High8.87.9AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:CSecurity Center - Brute Force EnumerationCVE-2026-19636Medium5.34.8AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N/E:P/RL:O/RC:CSecurity Center - Local Privilege EscalationCVE-2026-19635High8.87.9AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:CSecurity Center - SQL InjectionCVE-2026-19631Medium4.94.4AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:CSecurity Center - Privilege EscalationCVE-2026-19629High8.17.3AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:P/RL:O/RC:CSecurity Center - OS Command InjectionCVE-2026-19628High7.26.5AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:CSecurity Center - Remote Code ExecutionCVE-2026-19626Critical9.98.9AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:CcurlCVE-2026-11856Critical9.88.8AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:CcurlCVE-2026-11564Critical9.18.2AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:P/RL:O/RC:CcurlCVE-2026-5773High7.56.7AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:CcurlCVE-2026-12064High7.56.7AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:CcurlCVE-2026-11586High7.56.7AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:CcurlCVE-2026-3784Medium6.55.9AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:P/RL:O/RC:CcurlCVE-2026-5545Medium6.55.9AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:P/RL:O/RC:CcurlCVE-2026-4873Medium5.95.3AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:CunderscoreJSCVE-2026-27601Medium5.95.3AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C Tenable has released Security Center 6.9.0 to address these issues. The installation files can be obtained from the Tenable Downloads Portal: https://www.tenable.com/downloads/security-center

Details

Source: Mitre, NVD

Published: 2026-08-13

Risk Information

CVSS v2

Base Score: 9

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 4.9

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Severity: Medium