
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-57587 is a SQL injection vulnerability in Tenable Nessus that allows a remote, unauthenticated attacker who controls reverse DNS records for a scanned host to inject malicious SQL into the scan results database, potentially enabling exfiltration of scan-result data. It affects all Nessus versions prior to 10.12.1. The vulnerability was reported to Tenable on 2026-05-15, accepted on 2026-06-09, and patched with the release of Nessus 10.12.1 on 2026-06-25. It carries a CVSS v3.1 base score of 5.3 (Medium) and a CVSS v4.0 base score of 2.9 (Low) (Tenable Advisory, GitHub Advisory).
The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), where Nessus fails to properly sanitize reverse DNS record data returned during a scan before incorporating it into SQL queries against the scan results database. An attacker must control the reverse DNS (PTR) records for a host being scanned by Nessus; when Nessus performs a reverse DNS lookup on that host, the maliciously crafted PTR record value is passed unsanitized into a SQL statement. A companion vulnerability, CVE-2026-57588, involves SQL injection via scan result files injected by a privileged Nessus user (local attack vector). Both were discovered by Tristan Madani (@TristanInSec) from Talence Security (Tenable Advisory).
Successful exploitation of CVE-2026-57587 is limited to confidentiality impact — specifically, the potential exfiltration of data stored in the Nessus scan results database, which may include sensitive vulnerability assessment findings, host information, and network topology details. There is no integrity or availability impact identified. Because Nessus scan results can contain detailed information about an organization's attack surface, unauthorized access to this data could significantly aid further targeted attacks (Tenable Advisory, GitHub Advisory).
No public proof-of-concept exploit code or active in-the-wild exploitation has been observed as of the time of disclosure (Feedly). The CVSS v4.0 exploit maturity is rated "Proof of Concept" (E:P), suggesting limited exploit development activity. The EPSS score is approximately 0.339% (26th percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the attacker to control reverse DNS infrastructure for a host that is actively being scanned by a vulnerable Nessus instance, which is a non-trivial precondition (Tenable Advisory, GitHub Advisory).
'; INSERT INTO results SELECT ...; -- or a UNION-based payload designed to exfiltrate data from the scan results database).Tenable has released Nessus version 10.12.1 to address CVE-2026-57587 (and the related CVE-2026-57588). Users should upgrade to Nessus 10.12.1 or later immediately via the Tenable Downloads Portal. As a defense-in-depth measure, administrators should implement DNS validation controls to restrict the ability of untrusted parties to influence reverse DNS records used during Nessus scan operations, and limit Nessus scan scopes to trusted, internally controlled IP ranges where possible (Tenable Advisory).
Tenable issued security advisory TNS-2026-17 crediting Tristan Madani (@TristanInSec) from Talence Security for responsible disclosure of the vulnerability. No significant broader media coverage or notable community commentary beyond the official advisory and standard vulnerability database entries has been identified at this time (Tenable Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."