MEDIUM

CVE-2026-57587

Tenable Nessus 2026-06-25 CVSS v3.1
CVSS
5.3

Description

A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a scanned host to inject malicious SQL into the scan results database, potentially enabling exfiltration of scan-result data.

Summary dbcve.org

SQL injection vulnerability in Tenable Nessus allows remote, unauthenticated attackers who control reverse DNS records for a scanned host to inject malicious SQL queries into the scan results database, potentially enabling exfiltration of sensitive scan-result data.

Mitigation

Implement strict access controls on DNS record management, validate DNS responses before using them in SQL queries, apply vendor patches when available, and consider network segmentation to limit exposure of the Nessus backend database.

Weakness (CWE)

CWE-89 SQL Injection

EPSS Score

0.45%
Probability of exploitation in next 30 days
38.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE