Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Tenable has released Security Center Patch SC202607.1 to address these issues. The installation files can be obtained from the Tenable Downloads Portal: https://www.tenable.com/downloads/security-center
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.tenable.com/security/tns-2026-19 |
|
Thu, 30 Jul 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | SQL Injection in Tenable Security Center Ticketing API Exposes Sensitive Data |
Mon, 27 Jul 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenable
Tenable security Center |
|
| Vendors & Products |
Tenable
Tenable security Center |
Mon, 27 Jul 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | SQL Injection in Tenable Security Center Ticketing API Allows Sensitive Data Access |
Fri, 24 Jul 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 24 Jul 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | SQL Injection in Tenable Security Center Ticketing API Allows Sensitive Data Access |
Tue, 21 Jul 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV4_0
|
Tue, 21 Jul 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database. | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2026-07-24T03:55:53.208Z
Reserved: 2026-07-20T19:19:24.798Z
Link: CVE-2026-64877
Updated: 2026-07-22T19:05:55.682Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-30T17:00:07Z
-
CWE-20
Improper Input Validation