Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Tenable has released Security Center Patch SC202607.1 to address these issues. The installation files can be obtained from the Tenable Downloads Portal: https://www.tenable.com/downloads/security-center
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.tenable.com/security/tns-2026-19 |
|
Wed, 22 Jul 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 21 Jul 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injection and unauthorized database read access. | |
| Title | Blind SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2026-07-22T18:25:28.118Z
Reserved: 2026-07-20T19:19:24.798Z
Link: CVE-2026-64880
Updated: 2026-07-22T18:13:56.649Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-24T21:15:02Z