CVE-2026-19679 is an input-validation vulnerability in Tenable Security Center for Linux before version 6.9.0. File-upload handling insufficiently sanitizes attacker-controlled filenames. A crafted filename can reach a downstream command-execution context, creating an OS command-injection condition.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a single Python exploit script (poc.py) and a README documenting the vulnerability, patch behavior, and example runs. The exploit targets Tenable Security Center’s audit-file upload/import workflow and demonstrates CVE-2026-19679: insufficient sanitization of uploaded tailoring filenames. The script authenticates to the target via /rest/token, stages files through the REST upload interface, then submits a crafted POST to /rest/auditFile with a metacharacter-bearing tailoringOriginalFilename to determine whether the target is vulnerable. The core capability is a differential probe: vulnerable versions accept the crafted filename and proceed deeper into processing, while 6.9.0 rejects it with "Invalid tailoring filename." The script also supports a combined-chain mode using the related CVE-2026-19681 sink, where a staged filename carries a shell payload and the exploit starts a local HTTP callback server to receive command output. Structurally, the code uses a small SC helper class for authenticated REST requests, embedded valid SCAP tailoring XML content, upload path candidates for staging, and logic to interpret server responses as patched/vulnerable. Overall, this is an operational PoC that can function as both a vulnerability probe and, when the companion flaw is present, an RCE demonstration.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced CVE in the Tenable SecurityCenter plugin entry; no specific details provided in the content.
An input validation vulnerability in Tenable Security Center file upload handling that could contribute to downstream command injection.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.