CVE-2026-64877
EUVD-2026-4635821.07.2026, 19:17
An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| tenable | security_center | 6.6.0 ≤ 𝑥 ≤ 6.8.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration