CVE-2026-64877 Details
Description
An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.
A SQL injection vulnerability has been identified in the ticketing REST API of Tenable Security Center. This flaw allows authenticated non-admin users to exploit the API and access sensitive data stored in the appliance database. The vulnerability affects Security Center versions 6.6.0 through 6.8.0.
Users can upgrade to Tenable Security Center Patch SC202607.1, which is available through the Tenable Downloads Portal, to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.tenable.com/security/tns-2026-19 | [email protected] | PatchThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| tenable security center | >= 6.6.0, <= 6.8.0 |
CPE
Remediation
| |
| linux linux kernel | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 18, 2026 | Initial Analysis | [email protected] |
| Jul 24, 2026 | CVE Modified | CISA-ADP |
| Jul 22, 2026 | CVE Modified | CISA-ADP |
| Jul 21, 2026 | CVE Modified | [email protected] |
| Jul 21, 2026 | New CVE Received | [email protected] |