Tenable published fixes for four vulnerabilities in Tenable Enclave Security 1.8.0 and earlier, including one critical flaw and three high-severity bugs. The issues are already addressed in Enclave Security 1.9.0 and patch SC-202608, which also includes Tenable Security Center 6.9.0.
The standout bug is CVE-2026-19626: a logged-in, non-admin user can feed specially crafted input into report generation, and the server processes it unsafely and runs code with the service account’s privileges. Another flaw, CVE-2026-19629, lets a security admin with user-management rights in one group edit users in other groups, breaking the product’s intended access boundaries.
For teams using delegated administration or the reporting feature, the exposure is not limited to one server-side code path. A patch may close the exploit, but multi-group deployments still need to treat role separation as part of the trust boundary the product is supposed to enforce.