Tenable Nessus 10.12.0 and Earlier Vulnerable to SQL Injection (CVE‑2026‑57588)
What Happened — A SQL injection flaw (CVE‑2026‑57588) exists in Tenable Nessus versions 10.12.0 and earlier when a privileged user imports a crafted .nessus XML file. Successful exploitation allows an attacker to run arbitrary SQL against the Nessus PostgreSQL backend and exfiltrate scan data.
Why It Matters for Compliance & Audit Readiness
- The vulnerability bypasses the “least‑privilege” principle (SOC 2 CC6.1) and could be used to tamper with or steal audit evidence stored in Nessus.
- Demonstrating continuous monitoring of third‑party tools and evidence of timely remediation is a core SOC 2 requirement for a defensible audit trail.
- Mapping this finding to your control library helps prove that you have identified, mitigated, and documented a critical security gap.
Who Is Affected — Any organization that relies on Tenable Nessus for vulnerability management, across healthcare, finance, cloud services, retail, and other sectors.
Recommended Actions —
- Upgrade to Nessus 10.12.1 or later immediately.
- Restrict the import of scan result files to a minimal set of privileged accounts and enforce MFA.
- Document the remediation in your SOC 2 evidence repository and map the finding to the “System Operations” and “Change Management” controls. Source: https://www.exploit-db.com/exploits/52620
Technical Notes — The flaw is a remote SQL injection triggered by a malicious .nessus file; CVSS 4.3 (Medium). Exploitation requires social engineering to convince a privileged user to import the file. The backend is PostgreSQL. Source: https://www.exploit-db.com/exploits/52620