Junglewise Threat Intelligence

CVE-2026-57588: Tenable Nessus SQL injection in scan result import

CVE-2026-57588 · Severity: low · CVSS 3.3 · Published 2026-06-25

Technologies: Tenable Nessus. Vendors: Tenable.

Executive brief

A vulnerability in the Nessus vulnerability scanner could allow an attacker to steal sensitive scan data. By tricking a legitimate user into importing a specially crafted, malicious scan result file, an attacker can execute unauthorized database commands. This could lead to the unauthorized exposure of internal security scan information, though it requires manual interaction from a user with import privileges.

Technical details

A SQL injection vulnerability (CWE-89) exists in Tenable Nessus due to improper neutralization of special elements within scan result files. An attacker can exploit this by crafting a malicious scan result file and social engineering a privileged user into importing it into the Nessus console. Upon import, the malicious SQL commands are executed against the underlying scan results database. This could allow an attacker to exfiltrate sensitive scan data. The vulnerability is addressed in Nessus version 10.12.1.

Affected products

  • Tenable Nessus < 10.12.1

Timeline

  • 2026-06-25: disclosed
  • 2026-06-25: advisory

References

Related threats