PatchSiren

Tenable, Inc. CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Tenable, Inc. CVE published 2026-08-14

CVE-2026-19681

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-14T18:17:23.480Z and has not been modified since then. This authenticated command injection vulnerability in Security Center related to file upload processing allows potential arbitrary command execution. Security teams should prioritize patching immediately. Affected operators and platforms should [truncated]

HIGH Tenable, Inc. CVE published 2026-08-14

CVE-2026-19629

A privilege escalation vulnerability exists in Tenable Security Center, allowing users with 'Security Manager' role and 'manage user' permission on a single group to modify users in other groups, bypassing intended access control restrictions. This vulnerability could allow an attacker to gain unauthorized access to sensitive information or systems. The vulnerability is considered high severity with a CVS [truncated]

HIGH Tenable, Inc. CVE published 2026-08-14

CVE-2026-19628

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-14T17:17:31.110Z and has not been modified since then. CVE-2026-19628 is a command injection vulnerability in Tenable Security Center, allowing authenticated administrators to achieve arbitrary command execution on the underlying operating system when specific backend operations are triggered. The v [truncated]

CRITICAL Tenable, Inc. CVE published 2026-08-14

CVE-2026-19626

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-14T17:17:30.940Z and has not been modified since then. The vulnerability exists in Tenable Security Center's report generation functionality, allowing an authenticated, non-administrative user to exploit the issue through specially crafted input, resulting in arbitrary code execution with service ac [truncated]

CRITICAL Tenable, Inc. CVE published 2026-08-03

CVE-2026-18667

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-03T23:16:45.590Z and has not been modified since then. This critical vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an operator to connect the sensor to an attacker-controlled host. The vulnerability can be exploited through a spec [truncated]

HIGH Tenable, Inc. CVE published 2026-07-21

CVE-2026-64881

CVE-2026-64881 is a HIGH severity vulnerability with a CVSS score of 8.7. The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection when chained with a related vulnerability. Security teams and administrators responsible for systems using the affected audit file upload handler shou [truncated]

HIGH Tenable, Inc. CVE published 2026-07-21

CVE-2026-64880

CVE-2026-64880 is a high-severity blind SQL injection vulnerability. The issue arises from unsanitized user-supplied input in report filtering parameters being concatenated directly into SQL queries without proper escaping or parameterized queries. This allows for unauthorized database read access. The CVE record was published on 2026-07-21T20:17:04.900Z and was last modified on 2026-07-22T20:35:40.827Z.

CRITICAL Tenable, Inc. CVE published 2026-07-21

CVE-2026-64879

CVE-2026-64879 is a critical vulnerability with a CVSS score of 9.4. A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality. The vulnerability arises from improper sanitization of filenames during file upload, which are then used [truncated]

CRITICAL Tenable, Inc. CVE published 2026-07-21

CVE-2026-64878

CVE-2026-64878 is a critical vulnerability in the Analysis REST endpoint of an affected product, allowing remote code execution as a low-privileged OS user. The vulnerability exists due to unvalidated input in asset filter parameters, which enables shell metacharacters to escape command argument handling. Users of affected products should review their configurations and apply patches or mitigations as ava [truncated]

CRITICAL Tenable, Inc. CVE published 2026-07-21

CVE-2026-64877

CVE-2026-64877 is a SQL injection vulnerability in the ticketing REST API of an appliance. An authenticated non-admin user can exploit this flaw to access sensitive data stored in the appliance database. The CVSS score for this vulnerability is 9.4, indicating a critical severity level. The vulnerability exists due to improper input validation in the ticketing REST API, allowing malicious SQL code injecti [truncated]

HIGH Tenable, Inc. CVE published 2026-04-23

CVE-2026-33694

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-23T19:17:28.073Z and has not been modified since then. This vulnerability affects Tenable Nessus and Nessus Agent products, allowing an attacker to create a junction and delete arbitrary files with SYSTEM privileges, potentially facilitating arbitrary code execution with elevated SYSTEM privileges. [truncated]