CVE-2026-64877
8.4
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Summary
An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Tenable, Inc. | Security Center | 0 < 6.8.0 | unaffected |
Weaknesses
- CWE-20: CWE-20 Improper input validation
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.