CVE-2026-19636CWE-1270
CVE-2026-19636
Medium · published August 14, 2026
What it is
An issue was identified in which CSRF tokens were generated using a predictable method, potentially reducing their effectiveness as a security control. This has been addressed by improving the randomness and entropy of token generation.
The record
Technical detail
- CVSS v3.1
- 5.3 · MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
- CVSS v4.0
- 6.0 · CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS
- 0.00156 · 5.1th percentile
- Weakness
- CWE-1270 · Generation of Incorrect Security Tokens
- Published
- 2026-08-14T22:17Z
Affected products (1)
| Product | Versions | Fixed in |
|---|
| tenable/security_center | < 6.9.0 | 6.9.0 |
References (1)
EPSS history
Timeline