Full Report
Tenable, Inc. security advisory (AV26-820)
Analysis Summary
# Vulnerability: Multiple Vulnerabilities in Tenable Security Center
## CVE Details
- **CVE ID:** CVE-2026-3420, CVE-2026-3421, CVE-2026-3422 (and others addressed in the 6.9.0 rollup)
- **CVSS Score:** Up to 8.8 (High)
- **CWE:** Included but not limited to CWE-79 (Cross-site Scripting) and CWE-89 (SQL Injection)
## Affected Systems
- **Products:** Tenable Security Center (formerly Tenable.sc)
- **Versions:** All versions prior to 6.9.0
- **Configurations:** Default installations; specific vulnerabilities may require authenticated access to the web interface.
## Vulnerability Description
Tenable Security Center version 6.9.0 addresses multiple security flaws identified during internal audits and third-party reports. The primary vulnerabilities include:
1. **Stored Cross-Site Scripting (XSS):** Improper validation of user-supplied input allows an authenticated attacker to inject malicious scripts into certain dashboard elements.
2. **SQL Injection:** Vulnerabilities in specific API endpoints could allow an authenticated user to execute unauthorized queries against the underlying database.
3. **Information Disclosure:** Insecure handling of session tokens or configuration files could lead to the exposure of sensitive system data.
## Exploitation
- **Status:** Not currently reported as exploited in the wild.
- **Complexity:** Low to Medium
- **Attack Vector:** Network (Typically requires access to the Security Center management console)
## Impact
- **Confidentiality:** High (Potential access to vulnerability data and system configurations)
- **Integrity:** High (Unauthorized modification of security policies or scan results)
- **Availability:** Medium (Potential for service disruption through database manipulation)
## Remediation
### Patches
- **Tenable Security Center 6.9.0:** Users should upgrade to version 6.9.0 or later immediately.
- Patches are available via the Tenable Downloads portal.
### Workarounds
- **Network Segmentation:** Limit access to the Security Center web interface to trusted administrative networks only.
- **Least Privilege:** Ensure users are granted only the minimum necessary permissions within the application to reduce the impact of an authenticated exploit.
## Detection
- **Indicators of Compromise:** Unusual administrative activity in audit logs; unexpected SQL syntax errors in application logs; unauthorized changes to user roles.
- **Detection methods and tools:** Use Tenable’s own plugins (e.g., Plugin ID 204561) to scan for outdated versions of Security Center within your environment.
## References
- **Vendor Advisory:** hxxps[://]www[.]tenable[.]com/security/tns-2026-22
- **Cyber Centre Advisory:** hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/tenable-inc-security-advisory-av26-820