PT-2026-62039 · Tenable · Securitycenter

CVE-2026-64877

·

Published

2026-07-21

·

Updated

2026-07-21

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-64877

Affected Products

Securitycenter