# Tenable Nessus SQL injection flaws patched

Published: 2026-06-26 · Severity: medium
Canonical: https://vorant.io/reports/2c1587b2-522b-5e57-8c86-ac6e2050b1c6/tenable-nessus-sql-injection-flaws-patched

> Multiple SQL injection vulnerabilities in Tenable Nessus versions before 10.12.0 allow attackers to execute malicious SQL queries.

Tenable has disclosed multiple SQL injection (SQLi) vulnerabilities affecting Nessus versions prior to 10.12.0. These flaws enable an attacker to inject and execute arbitrary SQL commands against the application's database. SQL injection vulnerabilities can lead to unauthorized data access, modification, or deletion, depending on the database privileges and the application's architecture.

The vulnerabilities are tracked as CVE-2026-57587 and CVE-2026-57588. Tenable released security bulletin TNS-2026-17 on June 24, 2026, providing patches in Nessus version 10.12.0. Organizations running affected versions should prioritize upgrading to the patched release to mitigate exploitation risk.

Given that Nessus is a widely-deployed vulnerability scanner with privileged access to network infrastructure and sensitive scan data, these SQLi flaws represent a significant risk if exploited. However, there is no indication of active in-the-wild exploitation at this time.

## Mentioned in this report

- Vulnerabilities: CVE-2026-57587, CVE-2026-57588 (poc)

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0804

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/2c1587b2-522b-5e57-8c86-ac6e2050b1c6/tenable-nessus-sql-injection-flaws-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
