IT

Tracker / CVE-2026-64877

CVE-2026-64877

High 8.4

An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.

Affected products and versions

tenable security_center · 6.6.0 → 6.8.0

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References