CVE-2026-57587: SQL Injection in Nessus via Reverse DNS Lookup
Published Jun 25, 2026
·Updated
A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a scanned host to inject malicious SQL into the scan results database, potentially enabling exfiltration of scan-result data.
Affected Software
2 affected components
Tenable Nessus
Tenable Nessus<10.12.1
Event History
Jun 25, 2026
CVE Published
via MITRE·01:47 PM
Data Sourced
via MITRE·01:47 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-57587?
The severity of CVE-2026-57587 is rated as low with a score of 2.9.
2
How do I fix CVE-2026-57587?
To fix CVE-2026-57587, users should ensure they are using the latest version of Tenable Nessus that addresses this vulnerability.
3
What type of vulnerability is CVE-2026-57587?
CVE-2026-57587 is classified as an SQL Injection vulnerability.
4
Who can exploit CVE-2026-57587?
A remote, unauthenticated attacker who controls reverse DNS records can exploit CVE-2026-57587.
5
What impact can CVE-2026-57587 have on Tenable Nessus?
CVE-2026-57587 can enable an attacker to inject malicious SQL which may allow for the exfiltration of scan-result data.