CVE-2026-57588 is a SQL injection vulnerability in Tenable Nessus 10.12.0 and earlier. A maliciously crafted scan-result file can inject SQL into the Nessus scan-results database when a privileged user imports the file. Successful exploitation may expose data stored in Nessus scan results.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains a single substantial Python program (exploit.py), a README, license, and requirements file. The Python script is a standalone CLI exploitation framework rather than a framework module. It defines enums and dataclasses for payload templates, execution configuration, results, and validation; exposes subcommands such as generate, validate, list, and report; and is designed to generate malicious .nessus XML files that embed SQL injection payloads into importable scan data. The README claims the target is CVE-2026-57588 affecting Tenable Nessus 10.12.0 and prior during .nessus XML import, where attacker-controlled XML tag values are incorporated into backend PostgreSQL queries. Main exploit capability is malicious file generation for authenticated exploitation via Nessus import. The code and README indicate support for multiple SQLi styles (timing, boolean, error-based, stacked), database fingerprinting/enumeration, data exfiltration, file-read attempts, command execution, persistence, reverse shell, and DNS out-of-band exfiltration. Defaults in the code show attacker-controlled parameters such as callback_host, callback_port 4444, file_path /etc/passwd, command id, sleep_time 5, timeout 30, retries 3, and default exfil columns username/password_hash/email. The script also includes operational features like XML validation, hashing, logging, parallel jobs, and report generation. No hardcoded victim URL or direct exploitation HTTP endpoint is visible in the provided content; the exploit appears to operate primarily by producing a crafted file for later upload/import into Nessus by a privileged user. The most fingerprintable runtime observables from code are the local-IP discovery probe to 8.8.8.8:80, the default reverse-shell/callback port 4444, and default target artifacts such as /etc/passwd and the id command. Overall, this is an operational malicious-file generator for a claimed Nessus import SQL injection vulnerability, not merely a detector or README-only PoC.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.