Executive brief
Tenable Security Center, a platform used by organizations to manage and prioritize cyber risks, is affected by a security vulnerability in its reporting component. An attacker with basic user access could exploit this flaw to gain unauthorized access to information stored in the underlying database. This could lead to the exposure of sensitive security data or configuration details, potentially aiding further attacks against the organization's infrastructure.
Technical details
A blind SQL injection vulnerability exists in Tenable Security Center due to improper neutralization of user-supplied input within report filtering parameters. The application concatenates these parameters directly into SQL queries without adequate escaping or the use of parameterized queries. An authenticated attacker with low privileges can exploit this over the network to execute arbitrary SQL commands, leading to unauthorized read access to the database. Tenable has released patch SC202607.1 to address this issue in versions 6.6.0, 6.7.2, and 6.8.0.
Affected products
- Tenable, Inc. Security Center versions prior to 6.8.0; specifically 6.6.0, 6.7.2, and 6.8.0 are mentioned as patchable
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory
- 2026-07-21: patched: Patch SC202607.1 released