A command injection vulnerability in the Active Directory Events Listener of Tenable Identity Exposure (SaaS) allows an authenticated, low-privileged attacker to execute arbitrary commands as SYSTEM on the PDCe.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

To fully resolve this issue, existing installations must run Register-TenableIOA.ps1 -Uninstall and reinstall the listener after upgrading. Please see the full release notes for additional instructions. ( https://docs.tenable.com/identity-exposure.htm )


Workaround

No workaround given by the vendor.

History

Thu, 08 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
Description A command injection vulnerability in the Active Directory Events Listener of Tenable Identity Exposure (SaaS) allows an authenticated, low-privileged attacker to execute arbitrary commands as SYSTEM on the PDCe.
Title Command Injection
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published:

Updated: 2026-10-08T20:14:59.908Z

Reserved: 2026-10-06T15:41:52.906Z

Link: CVE-2026-106126

cve-icon Vulnrichment

Updated: 2026-10-08T20:14:56.301Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T20:17:29.950

Modified: 2026-10-08T21:17:51.547

Link: CVE-2026-106126

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T21:30:18Z

Weaknesses