TenableCVE-2026-64877
Tenable: SQL injection
Critical9.4CVE-2026-64877 · Published Jul 21, 2026 · updated Aug 18, 2026
An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-20
More Tenable advisories
All Tenable| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 29 | Tenable Link Library: cross-site scripting | Medium6.4 | 7.9.4 |
| Jul 21 | Tenable Security Center: command injection | High8.7 | 6.8.0 |
| Jul 21 | Tenable Security Center: remote code execution | Critical9.4 | 6.8.0 |
| Jul 21 | Tenable: command injection | Critical9.4 | No fix yet |
| Jul 21 | Tenable Security Center: SQL injection | High7.1 | 6.8.0 |
| Jul 14 | tenable_agent: path traversal | Critical9.4 | No fix yet |