Tenable Vulnerabilities and Affected Products
Vulnerabilities associated with Security Center.
Products
Clear product- Nessus20 vulnerabilities
- Security Center10 vulnerabilities
- Nessus Agent7 vulnerabilities
- Alcatel Lucent I-240W-Q GPON ONT6 vulnerabilities
- ASUSTOR Data Master6 vulnerabilities
- Agent4 vulnerabilities
- Nessus Network Monitor4 vulnerabilities
- nessus_agent4 vulnerabilities
- Tenable Identity Exposure4 vulnerabilities
- Tenable Nessus4 vulnerabilities
- LabKey Server Community Edition3 vulnerabilities
- nessus_network_monitor3 vulnerabilities
- SecurityCenter3 vulnerabilities
- Terrascan3 vulnerabilities
- Network Monitor2 vulnerabilities
- security_center2 vulnerabilities
- Burp Suite Community Edition1 vulnerability
- Check_MK1 vulnerability
- Grandstream GWN70001 vulnerability
- identity_exposure1 vulnerability
- integration-jira-cloud1 vulnerability
- libjpeg-turbo1 vulnerability
- MikroTik RouterOS1 vulnerability
- Tenable Appliance1 vulnerability
- Tenable Identity Exposure Secure Relay1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-2698MEDIUM | Generated title:Tenable Security Center Improper Access Control VulnerabilityAn improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope. CWE-639Feb 23, 2026 | CVSS5.7v4.0 | EPSS0.209% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Indirect Object Reference (IDOR) in Security CenterAn Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges via the 'owner' parameter. CWE-639Feb 23, 2026 | CVSS2.1v4.0 | EPSS0.205% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-2630HIGH | [R1] Stand-alone Security Patches Available for Tenable Security Center versions 6.5.1, 6.6.0 and 6.7.2: SC-202602.1 + SC-202602.2A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the underlying server where Tenable Security Center is hosted. CWE-78Feb 17, 2026 | CVSS7.4v4.0 | EPSS1.17% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Improper Access ControlIn Tenable Security Center versions prior to 6.7.0, an improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope. CWE-284Oct 8, 2025 | CVSS-v4.0 | EPSS0.181% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
An Improper Certificate Validation vulnerability exists in Tenable Security Center where an authenticated, privileged attacker could intercept email messages sent from Security Center via a rogue SMTP server. CWE-295Dec 9, 2024 | CVSS2.7v3.1 | EPSS0.177% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2024-5759MEDIUM | Improper privilege managementAn improper privilege management vulnerability exists in Tenable Security Center where an authenticated, remote attacker could view unauthorized objects and launch scans without having the required privileges CWE-269Jun 12, 2024 | CVSS5.4v3.1 | EPSS0.305% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Stored Cross Site ScriptingA stored cross site scripting vulnerability exists in Tenable Security Center where an authenticated, remote attacker could inject HTML code into a web application scan result page. CWE-79Jun 12, 2024 | CVSS3.5v3.1 | EPSS0.302% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2024-1471MEDIUM | HTML Injection VulnerabilityAn HTML injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Repository parameters, which could lead to HTML redirection attacks. | CVSS5.9v3.1 | EPSS0.406% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-1367HIGH | Command Injection Vulnerability in Tenable Security CenterA command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Logging parameters, which could lead to the execution of arbitrary code on the Security Center host. CWE-78Feb 14, 2024 | CVSS7.2v3.1 | EPSS1.56% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-2005MEDIUM | Tenable Plugin Feed ID #202306261202 Fixes Privilege Escalation VulnerabilityVulnerability in Tenable Tenable.Io, Tenable Nessus, Tenable Security Center.This issue affects Tenable.Io: before Plugin Feed ID #202306261202 ; Nessus: before Plugin Feed ID #202306261202 ; Security Center: before Plugin Feed ID #202306261202 . This vulnerability could allow a malicious actor with sufficient permissions on a scan target to place a binary in a specific filesystem location, and abuse the impacted plugin in order to escalate privileges. CWE-427Jun 26, 2023 | CVSS6.3v3.1 | EPSS0.378% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |