CVE-2026-57588: Tenable Nessus
Low severity, CVSS 3.3. EPSS: 0.3% chance of exploitation in the next 30 days.
A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by a privileged user, injects malicious SQL into the scan results database, potentially enabling exfiltration of scan-result data.
Affected products
- Tenable Nessus: before 10.12.1 (fixed in 10.12.1)
Published 2026-06-25. Last modified 2026-06-26.