Summary
- CVE-2026-19626 allows an authenticated non-administrative Security Center user to execute code through report generation.
- Additional vulnerabilities cover command injection and privilege escalation in Security Center and Enclave Security.
- CERT-FR is warning affected users, but the reviewed advisories do not report active exploitation.
Tenable has issued stand-alone security patches for vulnerabilities in Security Center and Enclave Security that can lead to remote code execution, command injection, and privilege escalation.
France’s CERT-FR highlighted the flaws on 31 August, listing remote arbitrary-code execution and privilege escalation among the risks. Its advisory covers Enclave Security releases before 1.9.0 and Security Center releases before 6.9.0.
The most serious issue is CVE-2026-19626, a Security Center report-generation vulnerability rated 9.9 under CVSS v3.1 and 9.4 under CVSS v4.
The flaw does not provide unauthenticated access. Tenable says an authenticated user without administrative privileges can supply specially crafted input that is processed unsafely during server-side report rendering, resulting in arbitrary code execution with the privileges of the Security Center service account.
That condition makes the distinction between initial access and privilege expansion important. An attacker would first need an authenticated Security Center account, but successful exploitation could cross the intended boundary between a low-privilege user and the underlying service.
Three additional vulnerabilities are included in the CERT-FR warning. CVE-2026-19628 involves operating-system command injection, CVE-2026-19629 provides a privilege-escalation path, and CVE-2026-19635 concerns local privilege escalation.
The exact prerequisites differ between the flaws, so the set should not be treated as four interchangeable remote vulnerabilities. CVE-2026-19626 is notable because low privileges are sufficient and no user interaction is required once the attacker has authenticated.
Tenable had already addressed the underlying issues in newer product versions. Late-August advisories added stand-alone patches for organisations running earlier supported releases.
Security Center patch SC-202608.1 is available for versions 6.6.0, 6.7.2, and 6.8.0 in Tenable’s specified configurations. A corresponding advisory covers Enclave Security 1.7.0 and 1.8.0.
The availability of stand-alone fixes is operationally significant for security-management systems, which can be difficult to upgrade immediately where they are integrated with scanning, reporting, asset inventories, and broader vulnerability-management processes.
Neither Tenable nor CERT-FR has said the vulnerabilities are under active exploitation. The evidence therefore supports a patching and exposure story rather than an active-incident claim.
The product class gives the flaws more weight than their scores alone. Security Center exists to aggregate information about organisational vulnerabilities and assets, meaning the management system itself can hold sensitive operational information and operate with extensive trust inside the environment.
Security tools consequently sit inside the attack surface they are designed to monitor. Scanners, consoles, endpoint-management systems, and orchestration platforms often require permissions and network reach that make compromise of the management layer particularly consequential.
CVE-2026-19626 demonstrates that risk clearly. An attacker who has already gained a low-privilege Security Center account could potentially turn that foothold into arbitrary code execution on the service.
That is a different threat model from an internet-facing unauthenticated flaw, but it can still become important after credential theft, insider misuse, or another compromise provides legitimate access.
CERT-FR is directing users to Tenable’s product-security advisories for remediation. The current evidence supports prompt patching of affected releases while maintaining the distinction between a critical technical weakness and a vulnerability known to be exploited in the wild.




