CVE-2026-57587
Tenable Nessus vulnerability analysis and mitigation

Overview

CVE-2026-57587 is a SQL injection vulnerability in Tenable Nessus that allows a remote, unauthenticated attacker who controls reverse DNS records for a scanned host to inject malicious SQL into the scan results database, potentially enabling exfiltration of scan-result data. It affects all Nessus versions prior to 10.12.1. The vulnerability was reported to Tenable on 2026-05-15, accepted on 2026-06-09, and patched with the release of Nessus 10.12.1 on 2026-06-25. It carries a CVSS v3.1 base score of 5.3 (Medium) and a CVSS v4.0 base score of 2.9 (Low) (Tenable Advisory, GitHub Advisory).

Technical details

The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), where Nessus fails to properly sanitize reverse DNS record data returned during a scan before incorporating it into SQL queries against the scan results database. An attacker must control the reverse DNS (PTR) records for a host being scanned by Nessus; when Nessus performs a reverse DNS lookup on that host, the maliciously crafted PTR record value is passed unsanitized into a SQL statement. A companion vulnerability, CVE-2026-57588, involves SQL injection via scan result files injected by a privileged Nessus user (local attack vector). Both were discovered by Tristan Madani (@TristanInSec) from Talence Security (Tenable Advisory).

Impact

Successful exploitation of CVE-2026-57587 is limited to confidentiality impact — specifically, the potential exfiltration of data stored in the Nessus scan results database, which may include sensitive vulnerability assessment findings, host information, and network topology details. There is no integrity or availability impact identified. Because Nessus scan results can contain detailed information about an organization's attack surface, unauthorized access to this data could significantly aid further targeted attacks (Tenable Advisory, GitHub Advisory).

Exploitability

No public proof-of-concept exploit code or active in-the-wild exploitation has been observed as of the time of disclosure (Feedly). The CVSS v4.0 exploit maturity is rated "Proof of Concept" (E:P), suggesting limited exploit development activity. The EPSS score is approximately 0.339% (26th percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the attacker to control reverse DNS infrastructure for a host that is actively being scanned by a vulnerable Nessus instance, which is a non-trivial precondition (Tenable Advisory, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify organizations using Tenable Nessus for vulnerability scanning (e.g., via job postings, technology fingerprinting, or network enumeration). Determine IP ranges that the target Nessus instance is likely to scan.
  2. Acquire control of reverse DNS: Gain control of a PTR (reverse DNS) record for an IP address within the target's scan scope. This could be achieved by owning or compromising a host in the scanned range, or by controlling DNS infrastructure for an IP block the attacker owns.
  3. Craft malicious PTR record: Set the PTR record for the controlled IP to a value containing a SQL injection payload (e.g., '; INSERT INTO results SELECT ...; -- or a UNION-based payload designed to exfiltrate data from the scan results database).
  4. Trigger a Nessus scan: Wait for or induce the target Nessus instance to scan the attacker-controlled IP address. Nessus will perform a reverse DNS lookup, retrieve the malicious PTR record, and pass it unsanitized into a SQL query.
  5. Exfiltrate scan data: Depending on the SQL injection technique used (e.g., error-based, time-based blind, or out-of-band), retrieve scan result data from the Nessus database, potentially including vulnerability findings, host details, and network topology information (Tenable Advisory).

Indicators of compromise

  • Network: Unusual or unexpected PTR (reverse DNS) record values returned during Nessus scan operations containing SQL metacharacters (e.g., single quotes, double dashes, UNION, SELECT keywords).
  • Logs: Nessus application logs showing SQL errors or anomalous query behavior correlated with reverse DNS lookups; database error messages referencing unexpected SQL syntax in hostname fields.
  • Database: Unexpected or anomalous entries in the Nessus scan results database; evidence of unauthorized data reads or unusual query patterns in database audit logs.
  • DNS: DNS query logs showing lookups for attacker-controlled IP addresses returning hostnames with SQL injection strings.

Mitigation and workarounds

Tenable has released Nessus version 10.12.1 to address CVE-2026-57587 (and the related CVE-2026-57588). Users should upgrade to Nessus 10.12.1 or later immediately via the Tenable Downloads Portal. As a defense-in-depth measure, administrators should implement DNS validation controls to restrict the ability of untrusted parties to influence reverse DNS records used during Nessus scan operations, and limit Nessus scan scopes to trusted, internally controlled IP ranges where possible (Tenable Advisory).

Community reactions

Tenable issued security advisory TNS-2026-17 crediting Tristan Madani (@TristanInSec) from Talence Security for responsible disclosure of the vulnerability. No significant broader media coverage or notable community commentary beyond the official advisory and standard vulnerability database entries has been identified at this time (Tenable Advisory).

Additional resources


SourceThis report was generated using AI

Related Tenable Nessus vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-36640HIGH7.3
  • Tenable Nessus logoTenable Nessus
  • cpe:2.3:a:tenable:nessus
NoYesJan 13, 2026
CVE-2025-36630HIGH7.1
  • Tenable Nessus logoTenable Nessus
  • cpe:2.3:a:tenable:nessus
NoYesJul 02, 2025
CVE-2025-36625MEDIUM4.3
  • Tenable Nessus logoTenable Nessus
  • cpe:2.3:a:tenable:nessus
NoYesApr 18, 2025
CVE-2026-57587LOW2.9
  • Tenable Nessus logoTenable Nessus
  • cpe:2.3:a:tenable:nessus
NoYesJun 25, 2026
CVE-2026-57588LOW1.8
  • Tenable Nessus logoTenable Nessus
  • cpe:2.3:a:tenable:nessus
NoYesJun 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management