CVE-2026-64880

Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injection and unauthorized database read access.
References
Link Resource
https://www.tenable.com/security/tns-2026-19 Patch Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:tenable:security_center:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-21 20:17

Updated : 2026-08-18 17:58


NVD link : CVE-2026-64880

Mitre link : CVE-2026-64880

CVE.ORG link : CVE-2026-64880


JSON object : View

Products Affected

tenable

  • security_center

linux

  • linux_kernel
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')