CVE-2026-2630Disclosure

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the underlying server where Tenable Security Center is hosted.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-02-17); latest day: 1
  • 8 total mentions across 4 days

Deep dive

Activity timeline8 mentions / 4d
01223Mentions · 2026-02-17: 3Mentions · 2026-02-18: 3Mentions · 2026-02-23: 1Mentions · 2026-03-31: 1Patch / Workaround · 2026-02-17: 2Patch / Workaround · 2026-02-18: 1Technical Details · 2026-02-17: 3Technical Details · 2026-02-18: 3Technical Details · 2026-03-31: 102-1702-1802-2303-31
Signal classification3 categories
Disclosure
450.0%
Patch
337.5%
General
112.5%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-173
Disclosure1Patch2
2026-02-183
Disclosure2Patch1
2026-02-231
General1
2026-03-311
Disclosure1
Full discourse8 posts
  • GovCERT.CZ@GOVCERT_CZ
    Patch

    🚨 Upozorňujeme na kritickou zranitelnost v Tenable Security Center, CVE-2026-2630. Jedná se o zranitelnost typu command injection s hodnocením CVSS 9.9, která umožňuje vzdálenému, autentizovanému útočníkovi spustit libovolný kód na serveru, kde běží Tenable Security Center. Úspěšné zneužití může vést k plnému kompromitování hostitelského systému. K útoku jsou potřeba platné přihlašovací údaje do webového rozhraní Tenable Security Center (pravděpodobně s vyššími oprávněními). Po autentizaci lze zranitelnost zneužít vzdáleně, bez dalších omezení. Zneužití probíhá vložením škodlivých znaků či metaznaků (např. ;, |, \`, &) do zranitelného vstupního pole, typicky v administrativních funkcích, jako jsou diagnostika, generování reportů či konfigurace systému. Aplikace předává vstup do systémového volání, což vede ke spuštění útočníkova příkazu. Vzhledem k tomu, že Tenable Security Center často běží s vysokými oprávněními (např. root nebo SYSTEM), může útočník získat úplnou kontrolu nad serverem, včetně možnosti exfiltrace dat, vytváření nových účtů nebo nasazení trvalých backdoorů. 📌Doporučujeme aplikovat Patch SC-202602.2.

    Post summary

    The post discloses a critical command‑injection flaw (CVE‑2026‑2630) in Tenable Security Center, explains how authenticated users can exploit it, and recommends applying patch SC‑202602.2.

    02030824
    4.2K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidad en productos Tenable ❗ CVE-2026-2630 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-tenable-2/ https://t.co/K4WIbWqK4h

    Post summary

    A tweet announces a vulnerability (CVE-2026-2630) in Tenable products and provides a link for more information.

    00011214
    6.6K followersView on X
  • Blue Team France@Blueteamfrance
    Disclosure

    CVE-2026-2630 — Tenable Security Center Injection de commandes via interface web Exécution côté serveur Compromission de la plateforme de gestion des vulnérabilités Accès aux scans et aux actifs https://nvd.nist.gov/vuln/detail/CVE-2026-2630

    Post summary

    CVE-2026-2630 is a command‑injection vulnerability in Tenable Security Center’s web interface that permits server‑side code execution, potentially compromising the vulnerability management platform and granting access to scans and assets.

    0000068
    6 followersView on X
  • Cyenetic Solutions@cyenetic
    Disclosure

    🚨 ALERT: CVE-2026-2630 – CVSS 9.9 A critical command injection flaw in Tenable Security Center (versions ≤6.7.2) allows authenticated remote code execution. Don't wait for a breach. Need help? ➡️ http://cyenetic.com #CVE20262630 #Tenable #CVE #Cyenetic https://t.co/xfE7a79ITG

    Post summary

    The tweet announces CVE-2026-2630, describing a command injection vulnerability with a high CVSS score, but offers no PoC, exploit code, active exploitation evidence, or patch information.

    0000049
  • CVE@CVEnew
    Disclosure

    CVE-2026-2630 A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the underlying server where Tenable Security Center is … https://www.cve.org/CVERecord?id=CVE-2026-2630

    Post summary

    CVE‑2026‑2630 is a command injection flaw allowing authenticated remote attackers to execute arbitrary code on Tenable Security Center servers; no PoC, exploit, patch, or active exploitation is reported.

    00000286
    56.4K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-2630: CRITICAL] A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the underlying server where Tenable Security Center is hosted.#cve,CVE-2026-2630,#cybersecurity https://cvefind.com/CVE-2026-2630

    Post summary

    A critical command injection vulnerability (CVE-2026-2630) in Tenable Security Center allows authenticated remote attackers to execute arbitrary code on the underlying server.

    0000062
    580 followersView on X
  • 0day Signal@0dayPublishing
    Patch

    🚨 CVE-2026-2630: [R1] Stand-alone Security Patches... Command injection in Tenable Security Center lets authenticated attackers pivot to full server compromise with minimal c... https://zerodaysignal.com/vulnerability/CVE-2026-2630 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑2630, a command injection flaw in Tenable Security Center that allows authenticated attackers to pivot to full server compromise, and notes that stand‑alone security patches are available.

    0000058
    131 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    ⚠️ CRITICAL OS Command Injection in Tenable Security Center (CVSS 9.9) lets authenticated attackers run code remotely. Restrict access & monitor activity now! Patch ASAP. https://radar.offseq.com/threat/cve-2026-2630-cwe-78-improper-neutralization-of-sp-3ee12498 #OffSeq #Tenab... https://t.co/z2WcvTiOoO

    Post summary

    The tweet highlights a critical OS Command Injection vulnerability in Tenable Security Center that allows remote code execution and urges users to apply a patch immediately.

    0000055
    265 followersView on X

Explore more