CVE-2026-19629: Tenable Security Center

High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.

A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission on a single group to modify users belonging to other groups. This bypasses the intended access control restrictions and enables unauthorized cross-group user management.

Affected products

  • Tenable Security Center: before 6.9.0 (fixed in 6.9.0)

Published 2026-08-14. Last modified 2026-08-19.