CVE-2026-19636CWE-1270

CVE-2026-19636

Medium · published August 14, 2026

CVSS v3.1
5.3
EPSS
0%
Percentile
5.1
In the wild
Unconfirmed
What it is

An issue was identified in which CSRF tokens were generated using a predictable method, potentially reducing their effectiveness as a security control. This has been addressed by improving the randomness and entropy of token generation.

The record
Technical detail
CVSS v3.1
5.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS v4.0
6.0 · CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS
0.00156 · 5.1th percentile
Weakness
CWE-1270 · Generation of Incorrect Security Tokens
Published
2026-08-14T22:17Z
Affected products (1)
ProductVersionsFixed in
tenable/security_center< 6.9.06.9.0
References (1)
EPSS history
Timeline
  • 14 AUG 17:24Z
    Insuffucient Protections Lead to Brute Force
    cvelistv5