HomeIntelligenceBrief
VULNERABILITY BRIEF🟡 Medium Vulnerability

SQL Injection (CVE‑2026‑57588) in Tenable Nessus 10.12.0 Allows Data Exfiltration via Malicious Scan Files

A SQL injection vulnerability (CVE‑2026‑57588) affects Tenable Nessus versions 10.12.0 and earlier when a privileged user imports a crafted .nessus file, potentially exposing scan data. This highlights the need for SOC 2‑aligned control mapping and continuous evidence collection around third‑party tools.

LiveThreat™ Intelligence · 📅 July 08, 2026· 📰 exploit-db.com
🟡
Severity
Medium
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
exploit-db.com

Tenable Nessus 10.12.0 and Earlier Vulnerable to SQL Injection (CVE‑2026‑57588)

What Happened — A SQL injection flaw (CVE‑2026‑57588) exists in Tenable Nessus versions 10.12.0 and earlier when a privileged user imports a crafted .nessus XML file. Successful exploitation allows an attacker to run arbitrary SQL against the Nessus PostgreSQL backend and exfiltrate scan data.

Why It Matters for Compliance & Audit Readiness

  • The vulnerability bypasses the “least‑privilege” principle (SOC 2 CC6.1) and could be used to tamper with or steal audit evidence stored in Nessus.
  • Demonstrating continuous monitoring of third‑party tools and evidence of timely remediation is a core SOC 2 requirement for a defensible audit trail.
  • Mapping this finding to your control library helps prove that you have identified, mitigated, and documented a critical security gap.

Who Is Affected — Any organization that relies on Tenable Nessus for vulnerability management, across healthcare, finance, cloud services, retail, and other sectors.

Recommended Actions

  • Upgrade to Nessus 10.12.1 or later immediately.
  • Restrict the import of scan result files to a minimal set of privileged accounts and enforce MFA.
  • Document the remediation in your SOC 2 evidence repository and map the finding to the “System Operations” and “Change Management” controls. Source: https://www.exploit-db.com/exploits/52620

Technical Notes — The flaw is a remote SQL injection triggered by a malicious .nessus file; CVSS 4.3 (Medium). Exploitation requires social engineering to convince a privileged user to import the file. The backend is PostgreSQL. Source: https://www.exploit-db.com/exploits/52620

📰 Original Source
https://www.exploit-db.com/exploits/52620

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →