CVE-2026-57588: SQL Injection in Nessus via Malicious Scan Result File Import
A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by a privileged user, injects malicious SQL into the scan results database, potentially enabling exfiltration of scan-result data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57588?
The severity of CVE-2026-57588 is classified as low with a score of 1.8.
How do I fix CVE-2026-57588?
To fix CVE-2026-57588, ensure that Tenable Nessus is updated to the latest version that addresses this vulnerability.
What impact does CVE-2026-57588 have on Tenable Nessus?
CVE-2026-57588 can potentially allow an attacker to exfiltrate scan-result data by exploiting SQL injection via a malicious scan result file.
What types of attacks can CVE-2026-57588 lead to?
CVE-2026-57588 can lead to data exfiltration from the scan results database if exploited successfully.
Who is affected by CVE-2026-57588?
Users of Tenable Nessus, particularly those with privileged access who import scan result files, are affected by CVE-2026-57588.