CVE-2026-106126

critical

Description

A command injection vulnerability in the Active Directory Events Listener of Tenable Identity Exposure (SaaS) allows an authenticated, low-privileged attacker to execute arbitrary commands as SYSTEM on the PDCe. Tenable has released TIE SaaS version 3.126.0 to address these issues. The installation files can be obtained from the Tenable Downloads Portal (https://www.tenable.com/downloads/identity-exposure).IMPORTANT: To fully resolve this issue, existing installations must run Register-TenableIOA.ps1 -Uninstall and reinstall the listener after upgrading. Please see the full release notes for additional instructions. (https://docs.tenable.com/identity-exposure.htm)

Details

Source: Mitre, NVD

Published: 2026-10-08

Risk Information

CVSS v2

Base Score: 9

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 9.9

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Severity: Critical