Impact
An SQL injection flaw exists in the ticketing REST API of Tenable Security Center, which can be triggered by an authenticated user who is not an administrator. Because user input is not properly validated, an attacker can inject arbitrary SQL commands that read data stored in the appliance database, potentially exposing confidential information. The vulnerability is classified as CWE-20 Input Validation.
Affected Systems
The affected product is Tenable Security Center. No specific version numbers are disclosed in the public data, so administrators should verify whether their installation includes the vulnerable functionality and check for the presence of the issued patch.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity, but the EPSS score is below 1%, suggesting that exploitation is currently unlikely in the wild. The flaw is not listed in the CISA KEV catalog. If an attacker possesses a valid non‑admin API credential, the attacker can read arbitrary data from the database by exploiting the HTTP endpoint; no privileged escalation or lateral movement is required for the data exposure. The vendor has released patch SC202607.1 to rectify the issue.
OpenCVE Enrichment