CVE-2026-19681 is an authenticated OS command injection vulnerability in Tenable Security Center for Linux prior to version 6.9.0. Improper handling of attacker-controlled data during file upload processing permits a low-privileged authenticated user to submit a specially crafted file whose contents are interpreted by the underlying operating system as commands.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains a Python proof-of-concept exploit (`poc.py`) and a detailed `README.md`. The exploit targets CVE-2026-19681 in Tenable Security Center, an authenticated command injection bug in file upload and SCAP audit file processing. The attack is a two-stage web/API chain: first, the attacker uploads a file with a malicious `context` value so shell metacharacters are preserved in the staged filename; second, the attacker calls `/rest/auditFile` with SCAP-related parameters so the server constructs a zip command using that filename without proper shell escaping. The PoC logs in to `/rest/token`, stages the malicious audit zip upload, stages a minimal SCAP tailoring XML upload, and then triggers the vulnerable `/rest/auditFile` workflow. It supports three practical modes: a timing-based `sleep` check, short direct command injection without exfiltration, and a more capable callback mode that starts a local HTTP server, injects a compact `curl|bash` one-liner, and prints returned command output. The code is operational rather than a simple detector because it automates authentication, upload staging, trigger execution, and output retrieval. Fingerprintable targets are primarily REST endpoints under `/rest`, plus fallback upload paths and attacker callback infrastructure. The README also documents vulnerable code locations, affected versions, patch behavior in 6.9.0, payload length constraints caused by PHP `tempnam()` truncation, and example successful runs showing execution as the web service user.
Repository contains a single Python exploit script (poc.py) and a README documenting the vulnerability, patch behavior, and example runs. The exploit targets Tenable Security Center’s audit-file upload/import workflow and demonstrates CVE-2026-19679: insufficient sanitization of uploaded tailoring filenames. The script authenticates to the target via /rest/token, stages files through the REST upload interface, then submits a crafted POST to /rest/auditFile with a metacharacter-bearing tailoringOriginalFilename to determine whether the target is vulnerable. The core capability is a differential probe: vulnerable versions accept the crafted filename and proceed deeper into processing, while 6.9.0 rejects it with "Invalid tailoring filename." The script also supports a combined-chain mode using the related CVE-2026-19681 sink, where a staged filename carries a shell payload and the exploit starts a local HTTP callback server to receive command output. Structurally, the code uses a small SC helper class for authenticated REST requests, embedded valid SCAP tailoring XML content, upload path candidates for staging, and logic to interpret server responses as patched/vulnerable. Overall, this is an operational PoC that can function as both a vulnerability probe and, when the companion flaw is present, an RCE demonstration.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced CVE in the Tenable SecurityCenter plugin entry; no specific details provided in the content.
An authenticated remote code execution / command injection vulnerability in Tenable Security Center, referenced via a Metasploit module name indicating audit file command injection.
An authenticated command injection vulnerability in Tenable Security Center's file upload processing that could allow arbitrary command execution on the underlying operating system.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.