MEDIUM
CVE-2026-57587
CVSS
5.3
Description
A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a scanned host to inject malicious SQL into the scan results database, potentially enabling exfiltration of scan-result data.
Summary dbcve.org
SQL injection vulnerability in Tenable Nessus allows remote, unauthenticated attackers who control reverse DNS records for a scanned host to inject malicious SQL queries into the scan results database, potentially enabling exfiltration of sensitive scan-result data.
Mitigation
Implement strict access controls on DNS record management, validate DNS responses before using them in SQL queries, apply vendor patches when available, and consider network segmentation to limit exposure of the Nessus backend database.
Weakness (CWE)
CWE-89
SQL Injection
EPSS Score
0.45%
Probability of exploitation in next 30 days
38.3th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.