What is CVE-2026-19629?
A privilege escalation vulnerability in Tenable Security Center allows a user with 'Security Manager' role and 'manage user' permission on a single group to modify users in other groups. This bypasses access controls and enables unauthorized cross-group user management. Affected organizations should apply the security patch released by Tenable immediately.
Azərbaycanca: Tenable Security Center-də imtiyaz yüksəltmə zəifliyi aşkarlanıb. Bu, yalnız bir qrup üzərində "Security Manager" rolu və "manage user" icazəsi olan istifadəçiyə digər qruplara mənsub istifadəçiləri dəyişməyə imkan verir. Təşkilatlar dərhal Tenable tərəfindən təqdim olunan təhlükəsizlik yamasını tətbiq etməlidirlər.
Related CVEs
link basis: shared vendor: Tenable
FAQ2
Which users can exploit the CVE-2026-19629 vulnerability in Tenable Security Center?
This vulnerability affects a user with the 'Security Manager' role and 'manage user' permission on a single group.
What action should be taken regarding the CVE-2026-19629 vulnerability?
Affected organizations should apply the security patch released by Tenable immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.