Junglewise Threat Intelligence

CVE-2026-64877: Tenable Security Center SQL injection in ticketing REST API

CVE-2026-64877 · Severity: critical · CVSS 9.6 · Published 2026-07-21

Technologies: Tenable, Inc. Security Center.

Executive brief

Tenable Security Center, a platform used for managing and prioritizing cyber risk, contains a vulnerability in its ticketing interface. An authenticated user without administrative privileges can exploit this flaw to access or modify sensitive data stored within the system's database. This could lead to the exposure of confidential security information or unauthorized changes to organizational data.

Technical details

A SQL injection vulnerability exists in the ticketing REST API of Tenable Security Center. The flaw is caused by improper input validation (CWE-20) of user-supplied data within API requests. An authenticated attacker with low-level privileges can send specially crafted network requests to execute arbitrary SQL commands against the underlying database. Successful exploitation allows for the unauthorized retrieval or modification of sensitive information. The vulnerability is addressed in Security Center patch SC202607.1 for versions 6.6.0, 6.7.2, and 6.8.0.

Affected products

  • Tenable, Inc. Security Center < 6.8.0

Timeline

  • 2026-07-21: advisory: Tenable released security advisory TNS-2026-19
  • 2026-07-21: patched: Patch SC202607.1 released to address the vulnerability

References