CVE-2026-106126: Tenable, Inc Tenable Identity Exposure Saas
Critical severity, CVSS 9.9. EPSS: 1.9% chance of exploitation in the next 30 days.
A command injection vulnerability in the Active Directory Events Listener of Tenable Identity Exposure (SaaS) allows an authenticated, low-privileged attacker to execute arbitrary commands as SYSTEM on the PDCe.
Affected products
- Tenable, Inc Tenable Identity Exposure Saas: before 3.126.0 (fixed in 3.126.0)
Published 2026-10-08. Last modified 2026-10-08.