CVE-2026-57588
A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by a privileged user, injects malicious SQL into the scan results database, potentially enabling exfiltration of scan-result data.
- Affected products
- Nessus
- Tenable Nessus
- < 10.12.1
- CVSS 4.0
- 4.6 MEDIUM
- CVSS 3.1
- 3.3 LOW
- EPSS
- 0.3% (25th percentile)
- Weakness
- CWE-89
- NVD status
- Analyzed
- Published
- 2026-06-25
CVE-2026-57588 at NVD
4 known exploits for CVE-2026-57588
Proof-of-concept code and exploit modules indexed by Sploitus