| CVE-2026-283897 | Tenable Identity Exposure leverages third-party software to help provide underlying functionality. Several of the third-party components (.NET Windows Server Hosting, NodeJS, Erlang OTP, SQL Server, OpenSSL, Curl) were found to contain vulnerabilities, and updated versions have been made available by the providers.Out of caution and in line with best practice, Tenable has opted to upgrade these components to address the potential impact of the issues. Tenable Identity Exposure version 3.93.5 updates .NET Windows Server Hosting to version 8.0.28.26269, NodeJS to version 20.20.2.0, Erlang OTP to version 26.2.5.21, SQL Server to version 15.0.4470.1, OpenSSL to version 4.0.1, and Curl to version 8.19.0 to address the identified vulnerabilities.Tenable Identity Exposure version v3.93.5 also resolves a vulnerability related to API endpoints returning information to unauthenticated GET requests (CVE-2026-13007).
p.subtitle { display: none; }
table { border-collapse: collapse; width: 100%; }
th { background: #1a1a2e; color: #fff; padding: 8px 10px; text-align: left; font-size: 12px; letter-spacing: 0.04em; white-space: nowrap; }
td { padding: 6px 10px; border-bottom: 1px solid #e5e7eb; vertical-align: top; }
tr:hover td { background: #f5f7ff; }
.cve-id { white-space: nowrap; }
.vector { font-size: 11px; color: #444; word-break: break-all; }
.score { font-weight: 600; white-space: nowrap; }
.lozenge.critical { color: #fff; }
.critical { color: #b91c1c; }
.high { color: #c2410c; }
.medium { color: #b45309; }
.low { color: #15803d; }
.badge { display: inline-block; padding: 1px 6px; border-radius: 3px; font-size: 11px; font-weight: 600; margin-right: 4px; }
.badge.critical { background: #fee2e2; color: #991b1b; }
.badge.high { background: #ffedd5; color: #9a3412; }
.badge.medium { background: #fef9c3; color: #854d0e; }
.badge.low { background: #dcfce7; color: #166534; }
.cwe { font-size: 12px; }
.empty { color: #aaa; }
.new-row td { background: #f0fdf4; }
.new-row:hover td { background: #dcfce7; }
CVE IDBase ScoreTemporal ScoreCVSSv3 VectorCVSSv4 Base ScoreCVSSv4 VectorCWEMEDIUMCVE-2025-111876.15.3CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H/E:U/RL:O/RC:C——CWE-121: Stack-based Buffer OverflowMEDIUMCVE-2025-130345.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-345: Insufficient Verification of Data AuthenticityMEDIUMCVE-2025-140176.35.5CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-416: Use After FreeMEDIUMCVE-2025-145245.34.6CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2025-148195.34.6CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2025-150795.34.6CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorLOWCVE-2025-152243.12.7CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2025-154678.87.6CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-416: Use After FreeMEDIUMCVE-2025-154685.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-154695.54.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlCRITICALCVE-2025-551309.17.9CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-287: Improper AuthenticationHIGHCVE-2025-551317.16.2CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')MEDIUMCVE-2025-551325.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C4.8CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:NCWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2025-552477.36.3CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementMEDIUMCVE-2025-552485.75CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorCRITICALCVE-2025-553159.98.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')HIGHCVE-2025-594657.56.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2025-594667.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-661995.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-681604.74.1CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-6941843.5CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2025-694197.46.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2025-694207.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2025-694217.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-19656.55.7CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlMEDIUMCVE-2026-26736.55.7CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:U/RL:O/RC:C——CWE-284: Improper Access ControlMEDIUMCVE-2026-37835.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-37846.55.7CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-38057.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-48735.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-55456.55.7CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-57737.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-62535.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-62767.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-64295.34.6CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-70095.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-71685.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-73838.17CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2026-90767.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-130077.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:NCWE-306: Missing Authentication for Critical Function; CWE-524: Use of Cache Containing Sensitive InformationHIGHCVE-2026-212187.56.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:NCWE-284: Improper Access ControlHIGHCVE-2026-212628.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-216377.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-217107.56.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-217135.95.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-217145.34.6CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionLOWCVE-2026-217153.32.9CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorLOWCVE-2026-217163.32.9CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlMEDIUMCVE-2026-217175.95.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-227955.54.8CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-227965.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-261307.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-261717.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-283867.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-125: Out-of-bounds ReadHIGHCVE-2026-283878.17CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2026-283887.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-283897.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-283907.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionCRITICALCVE-2026-317899.88.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-119: Improper Restriction of Operations within the Bounds of a Memory BufferHIGHCVE-2026-317907.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-321677.86.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')MEDIUMCVE-2026-321754.33.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-321767.86.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')HIGHCVE-2026-321777.36.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementHIGHCVE-2026-321787.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-322037.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-331167.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-331208.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-822: Untrusted Pointer DereferenceHIGHCVE-2026-341807.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-341817.46.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationCRITICALCVE-2026-341829.17.9CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-287: Improper AuthenticationHIGHCVE-2026-341837.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-3518854.4CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-354337.36.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementHIGHCVE-2026-403708.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-73: External Control of File Name or PathHIGHCVE-2026-427647.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-427657.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-427665.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-427675.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionLOWCVE-2026-427683.73.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-427695.34.6CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorLOWCVE-2026-427703.73.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-427716.25.4CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-427894.84.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C7CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:NCWE-295: Improper Certificate ValidationHIGHCVE-2026-427908.17CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C7.6CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:NCWE-295: Improper Certificate ValidationHIGHCVE-2026-428997.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-454457.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-454464.84.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2026-454478.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-287: Improper AuthenticationHIGHCVE-2026-454907.86.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementMEDIUMCVE-2026-454915.54.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-455917.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource Consumption
Tenable has released Tenable Identity Exposure version 3.93.5 to address these issues. The installation files can be obtained from the Tenable Downloads Portal: https://www.tenable.com/downloads/identity-exposure | high | |
| CVE-2026-283907 | Tenable Identity Exposure leverages third-party software to help provide underlying functionality. Several of the third-party components (.NET Windows Server Hosting, NodeJS, Erlang OTP, SQL Server, OpenSSL, Curl) were found to contain vulnerabilities, and updated versions have been made available by the providers.Out of caution and in line with best practice, Tenable has opted to upgrade these components to address the potential impact of the issues. Tenable Identity Exposure version 3.93.5 updates .NET Windows Server Hosting to version 8.0.28.26269, NodeJS to version 20.20.2.0, Erlang OTP to version 26.2.5.21, SQL Server to version 15.0.4470.1, OpenSSL to version 4.0.1, and Curl to version 8.19.0 to address the identified vulnerabilities.Tenable Identity Exposure version v3.93.5 also resolves a vulnerability related to API endpoints returning information to unauthenticated GET requests (CVE-2026-13007).
p.subtitle { display: none; }
table { border-collapse: collapse; width: 100%; }
th { background: #1a1a2e; color: #fff; padding: 8px 10px; text-align: left; font-size: 12px; letter-spacing: 0.04em; white-space: nowrap; }
td { padding: 6px 10px; border-bottom: 1px solid #e5e7eb; vertical-align: top; }
tr:hover td { background: #f5f7ff; }
.cve-id { white-space: nowrap; }
.vector { font-size: 11px; color: #444; word-break: break-all; }
.score { font-weight: 600; white-space: nowrap; }
.lozenge.critical { color: #fff; }
.critical { color: #b91c1c; }
.high { color: #c2410c; }
.medium { color: #b45309; }
.low { color: #15803d; }
.badge { display: inline-block; padding: 1px 6px; border-radius: 3px; font-size: 11px; font-weight: 600; margin-right: 4px; }
.badge.critical { background: #fee2e2; color: #991b1b; }
.badge.high { background: #ffedd5; color: #9a3412; }
.badge.medium { background: #fef9c3; color: #854d0e; }
.badge.low { background: #dcfce7; color: #166534; }
.cwe { font-size: 12px; }
.empty { color: #aaa; }
.new-row td { background: #f0fdf4; }
.new-row:hover td { background: #dcfce7; }
CVE IDBase ScoreTemporal ScoreCVSSv3 VectorCVSSv4 Base ScoreCVSSv4 VectorCWEMEDIUMCVE-2025-111876.15.3CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H/E:U/RL:O/RC:C——CWE-121: Stack-based Buffer OverflowMEDIUMCVE-2025-130345.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-345: Insufficient Verification of Data AuthenticityMEDIUMCVE-2025-140176.35.5CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-416: Use After FreeMEDIUMCVE-2025-145245.34.6CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2025-148195.34.6CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2025-150795.34.6CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorLOWCVE-2025-152243.12.7CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2025-154678.87.6CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-416: Use After FreeMEDIUMCVE-2025-154685.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-154695.54.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlCRITICALCVE-2025-551309.17.9CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-287: Improper AuthenticationHIGHCVE-2025-551317.16.2CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')MEDIUMCVE-2025-551325.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C4.8CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:NCWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2025-552477.36.3CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementMEDIUMCVE-2025-552485.75CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorCRITICALCVE-2025-553159.98.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')HIGHCVE-2025-594657.56.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2025-594667.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-661995.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-681604.74.1CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-6941843.5CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2025-694197.46.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2025-694207.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2025-694217.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-19656.55.7CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlMEDIUMCVE-2026-26736.55.7CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:U/RL:O/RC:C——CWE-284: Improper Access ControlMEDIUMCVE-2026-37835.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-37846.55.7CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-38057.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-48735.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-55456.55.7CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-57737.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-62535.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-62767.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-64295.34.6CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-70095.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-71685.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-73838.17CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2026-90767.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-130077.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:NCWE-306: Missing Authentication for Critical Function; CWE-524: Use of Cache Containing Sensitive InformationHIGHCVE-2026-212187.56.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:NCWE-284: Improper Access ControlHIGHCVE-2026-212628.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-216377.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-217107.56.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-217135.95.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-217145.34.6CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionLOWCVE-2026-217153.32.9CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorLOWCVE-2026-217163.32.9CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlMEDIUMCVE-2026-217175.95.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-227955.54.8CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-227965.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-261307.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-261717.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-283867.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-125: Out-of-bounds ReadHIGHCVE-2026-283878.17CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2026-283887.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-283897.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-283907.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionCRITICALCVE-2026-317899.88.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-119: Improper Restriction of Operations within the Bounds of a Memory BufferHIGHCVE-2026-317907.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-321677.86.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')MEDIUMCVE-2026-321754.33.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-321767.86.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')HIGHCVE-2026-321777.36.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementHIGHCVE-2026-321787.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-322037.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-331167.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-331208.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-822: Untrusted Pointer DereferenceHIGHCVE-2026-341807.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-341817.46.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationCRITICALCVE-2026-341829.17.9CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-287: Improper AuthenticationHIGHCVE-2026-341837.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-3518854.4CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-354337.36.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementHIGHCVE-2026-403708.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-73: External Control of File Name or PathHIGHCVE-2026-427647.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-427657.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-427665.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-427675.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionLOWCVE-2026-427683.73.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-427695.34.6CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorLOWCVE-2026-427703.73.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-427716.25.4CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-427894.84.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C7CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:NCWE-295: Improper Certificate ValidationHIGHCVE-2026-427908.17CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C7.6CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:NCWE-295: Improper Certificate ValidationHIGHCVE-2026-428997.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-454457.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-454464.84.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2026-454478.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-287: Improper AuthenticationHIGHCVE-2026-454907.86.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementMEDIUMCVE-2026-454915.54.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-455917.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource Consumption
Tenable has released Tenable Identity Exposure version 3.93.5 to address these issues. The installation files can be obtained from the Tenable Downloads Portal: https://www.tenable.com/downloads/identity-exposure | high | |
| CVE-2026-317899 | Tenable Identity Exposure leverages third-party software to help provide underlying functionality. Several of the third-party components (.NET Windows Server Hosting, NodeJS, Erlang OTP, SQL Server, OpenSSL, Curl) were found to contain vulnerabilities, and updated versions have been made available by the providers.Out of caution and in line with best practice, Tenable has opted to upgrade these components to address the potential impact of the issues. Tenable Identity Exposure version 3.93.5 updates .NET Windows Server Hosting to version 8.0.28.26269, NodeJS to version 20.20.2.0, Erlang OTP to version 26.2.5.21, SQL Server to version 15.0.4470.1, OpenSSL to version 4.0.1, and Curl to version 8.19.0 to address the identified vulnerabilities.Tenable Identity Exposure version v3.93.5 also resolves a vulnerability related to API endpoints returning information to unauthenticated GET requests (CVE-2026-13007).
p.subtitle { display: none; }
table { border-collapse: collapse; width: 100%; }
th { background: #1a1a2e; color: #fff; padding: 8px 10px; text-align: left; font-size: 12px; letter-spacing: 0.04em; white-space: nowrap; }
td { padding: 6px 10px; border-bottom: 1px solid #e5e7eb; vertical-align: top; }
tr:hover td { background: #f5f7ff; }
.cve-id { white-space: nowrap; }
.vector { font-size: 11px; color: #444; word-break: break-all; }
.score { font-weight: 600; white-space: nowrap; }
.lozenge.critical { color: #fff; }
.critical { color: #b91c1c; }
.high { color: #c2410c; }
.medium { color: #b45309; }
.low { color: #15803d; }
.badge { display: inline-block; padding: 1px 6px; border-radius: 3px; font-size: 11px; font-weight: 600; margin-right: 4px; }
.badge.critical { background: #fee2e2; color: #991b1b; }
.badge.high { background: #ffedd5; color: #9a3412; }
.badge.medium { background: #fef9c3; color: #854d0e; }
.badge.low { background: #dcfce7; color: #166534; }
.cwe { font-size: 12px; }
.empty { color: #aaa; }
.new-row td { background: #f0fdf4; }
.new-row:hover td { background: #dcfce7; }
CVE IDBase ScoreTemporal ScoreCVSSv3 VectorCVSSv4 Base ScoreCVSSv4 VectorCWEMEDIUMCVE-2025-111876.15.3CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H/E:U/RL:O/RC:C——CWE-121: Stack-based Buffer OverflowMEDIUMCVE-2025-130345.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-345: Insufficient Verification of Data AuthenticityMEDIUMCVE-2025-140176.35.5CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-416: Use After FreeMEDIUMCVE-2025-145245.34.6CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2025-148195.34.6CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2025-150795.34.6CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorLOWCVE-2025-152243.12.7CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2025-154678.87.6CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-416: Use After FreeMEDIUMCVE-2025-154685.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-154695.54.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlCRITICALCVE-2025-551309.17.9CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-287: Improper AuthenticationHIGHCVE-2025-551317.16.2CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')MEDIUMCVE-2025-551325.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C4.8CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:NCWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2025-552477.36.3CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementMEDIUMCVE-2025-552485.75CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorCRITICALCVE-2025-553159.98.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')HIGHCVE-2025-594657.56.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2025-594667.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-661995.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-681604.74.1CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-6941843.5CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2025-694197.46.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2025-694207.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2025-694217.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-19656.55.7CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlMEDIUMCVE-2026-26736.55.7CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:U/RL:O/RC:C——CWE-284: Improper Access ControlMEDIUMCVE-2026-37835.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-37846.55.7CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-38057.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-48735.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-55456.55.7CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-57737.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-62535.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-62767.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-64295.34.6CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-70095.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-71685.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-73838.17CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2026-90767.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-130077.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:NCWE-306: Missing Authentication for Critical Function; CWE-524: Use of Cache Containing Sensitive InformationHIGHCVE-2026-212187.56.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:NCWE-284: Improper Access ControlHIGHCVE-2026-212628.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-216377.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-217107.56.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-217135.95.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-217145.34.6CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionLOWCVE-2026-217153.32.9CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorLOWCVE-2026-217163.32.9CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlMEDIUMCVE-2026-217175.95.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-227955.54.8CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-227965.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-261307.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-261717.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-283867.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-125: Out-of-bounds ReadHIGHCVE-2026-283878.17CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2026-283887.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-283897.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-283907.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionCRITICALCVE-2026-317899.88.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-119: Improper Restriction of Operations within the Bounds of a Memory BufferHIGHCVE-2026-317907.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-321677.86.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')MEDIUMCVE-2026-321754.33.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-321767.86.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')HIGHCVE-2026-321777.36.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementHIGHCVE-2026-321787.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-322037.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-331167.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-331208.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-822: Untrusted Pointer DereferenceHIGHCVE-2026-341807.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-341817.46.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationCRITICALCVE-2026-341829.17.9CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-287: Improper AuthenticationHIGHCVE-2026-341837.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-3518854.4CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-354337.36.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementHIGHCVE-2026-403708.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-73: External Control of File Name or PathHIGHCVE-2026-427647.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-427657.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-427665.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-427675.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionLOWCVE-2026-427683.73.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-427695.34.6CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorLOWCVE-2026-427703.73.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-427716.25.4CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-427894.84.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C7CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:NCWE-295: Improper Certificate ValidationHIGHCVE-2026-427908.17CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C7.6CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:NCWE-295: Improper Certificate ValidationHIGHCVE-2026-428997.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-454457.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-454464.84.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2026-454478.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-287: Improper AuthenticationHIGHCVE-2026-454907.86.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementMEDIUMCVE-2026-454915.54.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-455917.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource Consumption
Tenable has released Tenable Identity Exposure version 3.93.5 to address these issues. The installation files can be obtained from the Tenable Downloads Portal: https://www.tenable.com/downloads/identity-exposure | high | |
| CVE-2026-317907 | Tenable Identity Exposure leverages third-party software to help provide underlying functionality. Several of the third-party components (.NET Windows Server Hosting, NodeJS, Erlang OTP, SQL Server, OpenSSL, Curl) were found to contain vulnerabilities, and updated versions have been made available by the providers.Out of caution and in line with best practice, Tenable has opted to upgrade these components to address the potential impact of the issues. Tenable Identity Exposure version 3.93.5 updates .NET Windows Server Hosting to version 8.0.28.26269, NodeJS to version 20.20.2.0, Erlang OTP to version 26.2.5.21, SQL Server to version 15.0.4470.1, OpenSSL to version 4.0.1, and Curl to version 8.19.0 to address the identified vulnerabilities.Tenable Identity Exposure version v3.93.5 also resolves a vulnerability related to API endpoints returning information to unauthenticated GET requests (CVE-2026-13007).
p.subtitle { display: none; }
table { border-collapse: collapse; width: 100%; }
th { background: #1a1a2e; color: #fff; padding: 8px 10px; text-align: left; font-size: 12px; letter-spacing: 0.04em; white-space: nowrap; }
td { padding: 6px 10px; border-bottom: 1px solid #e5e7eb; vertical-align: top; }
tr:hover td { background: #f5f7ff; }
.cve-id { white-space: nowrap; }
.vector { font-size: 11px; color: #444; word-break: break-all; }
.score { font-weight: 600; white-space: nowrap; }
.lozenge.critical { color: #fff; }
.critical { color: #b91c1c; }
.high { color: #c2410c; }
.medium { color: #b45309; }
.low { color: #15803d; }
.badge { display: inline-block; padding: 1px 6px; border-radius: 3px; font-size: 11px; font-weight: 600; margin-right: 4px; }
.badge.critical { background: #fee2e2; color: #991b1b; }
.badge.high { background: #ffedd5; color: #9a3412; }
.badge.medium { background: #fef9c3; color: #854d0e; }
.badge.low { background: #dcfce7; color: #166534; }
.cwe { font-size: 12px; }
.empty { color: #aaa; }
.new-row td { background: #f0fdf4; }
.new-row:hover td { background: #dcfce7; }
CVE IDBase ScoreTemporal ScoreCVSSv3 VectorCVSSv4 Base ScoreCVSSv4 VectorCWEMEDIUMCVE-2025-111876.15.3CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H/E:U/RL:O/RC:C——CWE-121: Stack-based Buffer OverflowMEDIUMCVE-2025-130345.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-345: Insufficient Verification of Data AuthenticityMEDIUMCVE-2025-140176.35.5CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-416: Use After FreeMEDIUMCVE-2025-145245.34.6CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2025-148195.34.6CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2025-150795.34.6CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorLOWCVE-2025-152243.12.7CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2025-154678.87.6CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-416: Use After FreeMEDIUMCVE-2025-154685.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-154695.54.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlCRITICALCVE-2025-551309.17.9CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-287: Improper AuthenticationHIGHCVE-2025-551317.16.2CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')MEDIUMCVE-2025-551325.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C4.8CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:NCWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2025-552477.36.3CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementMEDIUMCVE-2025-552485.75CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorCRITICALCVE-2025-553159.98.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')HIGHCVE-2025-594657.56.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2025-594667.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-661995.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-681604.74.1CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-6941843.5CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2025-694197.46.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2025-694207.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2025-694217.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-19656.55.7CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlMEDIUMCVE-2026-26736.55.7CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:U/RL:O/RC:C——CWE-284: Improper Access ControlMEDIUMCVE-2026-37835.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-37846.55.7CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-38057.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-48735.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-55456.55.7CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-57737.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-62535.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-62767.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-64295.34.6CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-70095.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-71685.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-73838.17CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2026-90767.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-130077.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:NCWE-306: Missing Authentication for Critical Function; CWE-524: Use of Cache Containing Sensitive InformationHIGHCVE-2026-212187.56.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:NCWE-284: Improper Access ControlHIGHCVE-2026-212628.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-216377.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-217107.56.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-217135.95.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-217145.34.6CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionLOWCVE-2026-217153.32.9CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorLOWCVE-2026-217163.32.9CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlMEDIUMCVE-2026-217175.95.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-227955.54.8CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-227965.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-261307.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-261717.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-283867.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-125: Out-of-bounds ReadHIGHCVE-2026-283878.17CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2026-283887.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-283897.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-283907.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionCRITICALCVE-2026-317899.88.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-119: Improper Restriction of Operations within the Bounds of a Memory BufferHIGHCVE-2026-317907.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-321677.86.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')MEDIUMCVE-2026-321754.33.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-321767.86.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')HIGHCVE-2026-321777.36.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementHIGHCVE-2026-321787.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-322037.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-331167.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-331208.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-822: Untrusted Pointer DereferenceHIGHCVE-2026-341807.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-341817.46.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationCRITICALCVE-2026-341829.17.9CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-287: Improper AuthenticationHIGHCVE-2026-341837.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-3518854.4CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-354337.36.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementHIGHCVE-2026-403708.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-73: External Control of File Name or PathHIGHCVE-2026-427647.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-427657.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-427665.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-427675.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionLOWCVE-2026-427683.73.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-427695.34.6CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorLOWCVE-2026-427703.73.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-427716.25.4CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-427894.84.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C7CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:NCWE-295: Improper Certificate ValidationHIGHCVE-2026-427908.17CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C7.6CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:NCWE-295: Improper Certificate ValidationHIGHCVE-2026-428997.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-454457.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-454464.84.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2026-454478.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-287: Improper AuthenticationHIGHCVE-2026-454907.86.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementMEDIUMCVE-2026-454915.54.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-455917.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource Consumption
Tenable has released Tenable Identity Exposure version 3.93.5 to address these issues. The installation files can be obtained from the Tenable Downloads Portal: https://www.tenable.com/downloads/identity-exposure | high | |
| CVE-2026-321777 | Tenable Identity Exposure leverages third-party software to help provide underlying functionality. Several of the third-party components (.NET Windows Server Hosting, NodeJS, Erlang OTP, SQL Server, OpenSSL, Curl) were found to contain vulnerabilities, and updated versions have been made available by the providers.Out of caution and in line with best practice, Tenable has opted to upgrade these components to address the potential impact of the issues. Tenable Identity Exposure version 3.93.5 updates .NET Windows Server Hosting to version 8.0.28.26269, NodeJS to version 20.20.2.0, Erlang OTP to version 26.2.5.21, SQL Server to version 15.0.4470.1, OpenSSL to version 4.0.1, and Curl to version 8.19.0 to address the identified vulnerabilities.Tenable Identity Exposure version v3.93.5 also resolves a vulnerability related to API endpoints returning information to unauthenticated GET requests (CVE-2026-13007).
p.subtitle { display: none; }
table { border-collapse: collapse; width: 100%; }
th { background: #1a1a2e; color: #fff; padding: 8px 10px; text-align: left; font-size: 12px; letter-spacing: 0.04em; white-space: nowrap; }
td { padding: 6px 10px; border-bottom: 1px solid #e5e7eb; vertical-align: top; }
tr:hover td { background: #f5f7ff; }
.cve-id { white-space: nowrap; }
.vector { font-size: 11px; color: #444; word-break: break-all; }
.score { font-weight: 600; white-space: nowrap; }
.lozenge.critical { color: #fff; }
.critical { color: #b91c1c; }
.high { color: #c2410c; }
.medium { color: #b45309; }
.low { color: #15803d; }
.badge { display: inline-block; padding: 1px 6px; border-radius: 3px; font-size: 11px; font-weight: 600; margin-right: 4px; }
.badge.critical { background: #fee2e2; color: #991b1b; }
.badge.high { background: #ffedd5; color: #9a3412; }
.badge.medium { background: #fef9c3; color: #854d0e; }
.badge.low { background: #dcfce7; color: #166534; }
.cwe { font-size: 12px; }
.empty { color: #aaa; }
.new-row td { background: #f0fdf4; }
.new-row:hover td { background: #dcfce7; }
CVE IDBase ScoreTemporal ScoreCVSSv3 VectorCVSSv4 Base ScoreCVSSv4 VectorCWEMEDIUMCVE-2025-111876.15.3CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H/E:U/RL:O/RC:C——CWE-121: Stack-based Buffer OverflowMEDIUMCVE-2025-130345.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-345: Insufficient Verification of Data AuthenticityMEDIUMCVE-2025-140176.35.5CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-416: Use After FreeMEDIUMCVE-2025-145245.34.6CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2025-148195.34.6CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2025-150795.34.6CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorLOWCVE-2025-152243.12.7CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2025-154678.87.6CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-416: Use After FreeMEDIUMCVE-2025-154685.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-154695.54.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlCRITICALCVE-2025-551309.17.9CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-287: Improper AuthenticationHIGHCVE-2025-551317.16.2CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')MEDIUMCVE-2025-551325.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C4.8CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:NCWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2025-552477.36.3CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementMEDIUMCVE-2025-552485.75CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorCRITICALCVE-2025-553159.98.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')HIGHCVE-2025-594657.56.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2025-594667.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-661995.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-681604.74.1CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-6941843.5CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2025-694197.46.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2025-694207.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2025-694217.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-19656.55.7CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlMEDIUMCVE-2026-26736.55.7CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:U/RL:O/RC:C——CWE-284: Improper Access ControlMEDIUMCVE-2026-37835.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-37846.55.7CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-38057.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-48735.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-55456.55.7CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-57737.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-62535.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-62767.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-64295.34.6CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-70095.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-71685.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-73838.17CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2026-90767.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-130077.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:NCWE-306: Missing Authentication for Critical Function; CWE-524: Use of Cache Containing Sensitive InformationHIGHCVE-2026-212187.56.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:NCWE-284: Improper Access ControlHIGHCVE-2026-212628.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-216377.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-217107.56.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-217135.95.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-217145.34.6CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionLOWCVE-2026-217153.32.9CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorLOWCVE-2026-217163.32.9CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlMEDIUMCVE-2026-217175.95.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-227955.54.8CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-227965.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-261307.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-261717.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-283867.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-125: Out-of-bounds ReadHIGHCVE-2026-283878.17CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2026-283887.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-283897.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-283907.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionCRITICALCVE-2026-317899.88.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-119: Improper Restriction of Operations within the Bounds of a Memory BufferHIGHCVE-2026-317907.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-321677.86.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')MEDIUMCVE-2026-321754.33.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-321767.86.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')HIGHCVE-2026-321777.36.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementHIGHCVE-2026-321787.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-322037.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-331167.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-331208.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-822: Untrusted Pointer DereferenceHIGHCVE-2026-341807.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-341817.46.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationCRITICALCVE-2026-341829.17.9CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-287: Improper AuthenticationHIGHCVE-2026-341837.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-3518854.4CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-354337.36.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementHIGHCVE-2026-403708.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-73: External Control of File Name or PathHIGHCVE-2026-427647.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-427657.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-427665.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-427675.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionLOWCVE-2026-427683.73.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-427695.34.6CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorLOWCVE-2026-427703.73.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-427716.25.4CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-427894.84.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C7CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:NCWE-295: Improper Certificate ValidationHIGHCVE-2026-427908.17CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C7.6CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:NCWE-295: Improper Certificate ValidationHIGHCVE-2026-428997.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-454457.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-454464.84.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2026-454478.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-287: Improper AuthenticationHIGHCVE-2026-454907.86.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementMEDIUMCVE-2026-454915.54.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-455917.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource Consumption
Tenable has released Tenable Identity Exposure version 3.93.5 to address these issues. The installation files can be obtained from the Tenable Downloads Portal: https://www.tenable.com/downloads/identity-exposure | high | |
| CVE-2026-331167 | Tenable Identity Exposure leverages third-party software to help provide underlying functionality. Several of the third-party components (.NET Windows Server Hosting, NodeJS, Erlang OTP, SQL Server, OpenSSL, Curl) were found to contain vulnerabilities, and updated versions have been made available by the providers.Out of caution and in line with best practice, Tenable has opted to upgrade these components to address the potential impact of the issues. Tenable Identity Exposure version 3.93.5 updates .NET Windows Server Hosting to version 8.0.28.26269, NodeJS to version 20.20.2.0, Erlang OTP to version 26.2.5.21, SQL Server to version 15.0.4470.1, OpenSSL to version 4.0.1, and Curl to version 8.19.0 to address the identified vulnerabilities.Tenable Identity Exposure version v3.93.5 also resolves a vulnerability related to API endpoints returning information to unauthenticated GET requests (CVE-2026-13007).
p.subtitle { display: none; }
table { border-collapse: collapse; width: 100%; }
th { background: #1a1a2e; color: #fff; padding: 8px 10px; text-align: left; font-size: 12px; letter-spacing: 0.04em; white-space: nowrap; }
td { padding: 6px 10px; border-bottom: 1px solid #e5e7eb; vertical-align: top; }
tr:hover td { background: #f5f7ff; }
.cve-id { white-space: nowrap; }
.vector { font-size: 11px; color: #444; word-break: break-all; }
.score { font-weight: 600; white-space: nowrap; }
.lozenge.critical { color: #fff; }
.critical { color: #b91c1c; }
.high { color: #c2410c; }
.medium { color: #b45309; }
.low { color: #15803d; }
.badge { display: inline-block; padding: 1px 6px; border-radius: 3px; font-size: 11px; font-weight: 600; margin-right: 4px; }
.badge.critical { background: #fee2e2; color: #991b1b; }
.badge.high { background: #ffedd5; color: #9a3412; }
.badge.medium { background: #fef9c3; color: #854d0e; }
.badge.low { background: #dcfce7; color: #166534; }
.cwe { font-size: 12px; }
.empty { color: #aaa; }
.new-row td { background: #f0fdf4; }
.new-row:hover td { background: #dcfce7; }
CVE IDBase ScoreTemporal ScoreCVSSv3 VectorCVSSv4 Base ScoreCVSSv4 VectorCWEMEDIUMCVE-2025-111876.15.3CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H/E:U/RL:O/RC:C——CWE-121: Stack-based Buffer OverflowMEDIUMCVE-2025-130345.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-345: Insufficient Verification of Data AuthenticityMEDIUMCVE-2025-140176.35.5CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-416: Use After FreeMEDIUMCVE-2025-145245.34.6CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2025-148195.34.6CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2025-150795.34.6CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorLOWCVE-2025-152243.12.7CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2025-154678.87.6CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-416: Use After FreeMEDIUMCVE-2025-154685.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-154695.54.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlCRITICALCVE-2025-551309.17.9CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-287: Improper AuthenticationHIGHCVE-2025-551317.16.2CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')MEDIUMCVE-2025-551325.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C4.8CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:NCWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2025-552477.36.3CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementMEDIUMCVE-2025-552485.75CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorCRITICALCVE-2025-553159.98.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')HIGHCVE-2025-594657.56.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2025-594667.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-661995.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-681604.74.1CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-6941843.5CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2025-694197.46.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2025-694207.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2025-694217.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-19656.55.7CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlMEDIUMCVE-2026-26736.55.7CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:U/RL:O/RC:C——CWE-284: Improper Access ControlMEDIUMCVE-2026-37835.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-37846.55.7CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-38057.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-48735.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-55456.55.7CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-57737.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-62535.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-62767.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-64295.34.6CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-70095.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-71685.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-73838.17CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2026-90767.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-130077.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:NCWE-306: Missing Authentication for Critical Function; CWE-524: Use of Cache Containing Sensitive InformationHIGHCVE-2026-212187.56.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:NCWE-284: Improper Access ControlHIGHCVE-2026-212628.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-216377.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-217107.56.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-217135.95.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-217145.34.6CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionLOWCVE-2026-217153.32.9CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorLOWCVE-2026-217163.32.9CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlMEDIUMCVE-2026-217175.95.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-227955.54.8CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-227965.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-261307.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-261717.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-283867.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-125: Out-of-bounds ReadHIGHCVE-2026-283878.17CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2026-283887.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-283897.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-283907.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionCRITICALCVE-2026-317899.88.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-119: Improper Restriction of Operations within the Bounds of a Memory BufferHIGHCVE-2026-317907.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-321677.86.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')MEDIUMCVE-2026-321754.33.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-321767.86.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')HIGHCVE-2026-321777.36.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementHIGHCVE-2026-321787.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-322037.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-331167.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-331208.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-822: Untrusted Pointer DereferenceHIGHCVE-2026-341807.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-341817.46.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationCRITICALCVE-2026-341829.17.9CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-287: Improper AuthenticationHIGHCVE-2026-341837.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-3518854.4CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-354337.36.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementHIGHCVE-2026-403708.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-73: External Control of File Name or PathHIGHCVE-2026-427647.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-427657.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-427665.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-427675.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionLOWCVE-2026-427683.73.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-427695.34.6CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorLOWCVE-2026-427703.73.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-427716.25.4CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-427894.84.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C7CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:NCWE-295: Improper Certificate ValidationHIGHCVE-2026-427908.17CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C7.6CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:NCWE-295: Improper Certificate ValidationHIGHCVE-2026-428997.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-454457.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-454464.84.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2026-454478.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-287: Improper AuthenticationHIGHCVE-2026-454907.86.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementMEDIUMCVE-2026-454915.54.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-455917.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource Consumption
Tenable has released Tenable Identity Exposure version 3.93.5 to address these issues. The installation files can be obtained from the Tenable Downloads Portal: https://www.tenable.com/downloads/identity-exposure | high | |
| CVE-2026-341817 | Tenable Identity Exposure leverages third-party software to help provide underlying functionality. Several of the third-party components (.NET Windows Server Hosting, NodeJS, Erlang OTP, SQL Server, OpenSSL, Curl) were found to contain vulnerabilities, and updated versions have been made available by the providers.Out of caution and in line with best practice, Tenable has opted to upgrade these components to address the potential impact of the issues. Tenable Identity Exposure version 3.93.5 updates .NET Windows Server Hosting to version 8.0.28.26269, NodeJS to version 20.20.2.0, Erlang OTP to version 26.2.5.21, SQL Server to version 15.0.4470.1, OpenSSL to version 4.0.1, and Curl to version 8.19.0 to address the identified vulnerabilities.Tenable Identity Exposure version v3.93.5 also resolves a vulnerability related to API endpoints returning information to unauthenticated GET requests (CVE-2026-13007).
p.subtitle { display: none; }
table { border-collapse: collapse; width: 100%; }
th { background: #1a1a2e; color: #fff; padding: 8px 10px; text-align: left; font-size: 12px; letter-spacing: 0.04em; white-space: nowrap; }
td { padding: 6px 10px; border-bottom: 1px solid #e5e7eb; vertical-align: top; }
tr:hover td { background: #f5f7ff; }
.cve-id { white-space: nowrap; }
.vector { font-size: 11px; color: #444; word-break: break-all; }
.score { font-weight: 600; white-space: nowrap; }
.lozenge.critical { color: #fff; }
.critical { color: #b91c1c; }
.high { color: #c2410c; }
.medium { color: #b45309; }
.low { color: #15803d; }
.badge { display: inline-block; padding: 1px 6px; border-radius: 3px; font-size: 11px; font-weight: 600; margin-right: 4px; }
.badge.critical { background: #fee2e2; color: #991b1b; }
.badge.high { background: #ffedd5; color: #9a3412; }
.badge.medium { background: #fef9c3; color: #854d0e; }
.badge.low { background: #dcfce7; color: #166534; }
.cwe { font-size: 12px; }
.empty { color: #aaa; }
.new-row td { background: #f0fdf4; }
.new-row:hover td { background: #dcfce7; }
CVE IDBase ScoreTemporal ScoreCVSSv3 VectorCVSSv4 Base ScoreCVSSv4 VectorCWEMEDIUMCVE-2025-111876.15.3CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H/E:U/RL:O/RC:C——CWE-121: Stack-based Buffer OverflowMEDIUMCVE-2025-130345.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-345: Insufficient Verification of Data AuthenticityMEDIUMCVE-2025-140176.35.5CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-416: Use After FreeMEDIUMCVE-2025-145245.34.6CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2025-148195.34.6CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2025-150795.34.6CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorLOWCVE-2025-152243.12.7CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2025-154678.87.6CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-416: Use After FreeMEDIUMCVE-2025-154685.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-154695.54.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlCRITICALCVE-2025-551309.17.9CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-287: Improper AuthenticationHIGHCVE-2025-551317.16.2CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')MEDIUMCVE-2025-551325.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C4.8CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:NCWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2025-552477.36.3CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementMEDIUMCVE-2025-552485.75CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorCRITICALCVE-2025-553159.98.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')HIGHCVE-2025-594657.56.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2025-594667.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-661995.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-681604.74.1CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-6941843.5CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2025-694197.46.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2025-694207.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2025-694217.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-19656.55.7CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlMEDIUMCVE-2026-26736.55.7CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:U/RL:O/RC:C——CWE-284: Improper Access ControlMEDIUMCVE-2026-37835.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-37846.55.7CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-38057.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-48735.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-55456.55.7CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-57737.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-62535.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-62767.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-64295.34.6CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-70095.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-71685.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-73838.17CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2026-90767.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-130077.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:NCWE-306: Missing Authentication for Critical Function; CWE-524: Use of Cache Containing Sensitive InformationHIGHCVE-2026-212187.56.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:NCWE-284: Improper Access ControlHIGHCVE-2026-212628.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-216377.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-217107.56.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-217135.95.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-217145.34.6CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionLOWCVE-2026-217153.32.9CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorLOWCVE-2026-217163.32.9CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlMEDIUMCVE-2026-217175.95.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-227955.54.8CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-227965.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-261307.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-261717.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-283867.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-125: Out-of-bounds ReadHIGHCVE-2026-283878.17CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2026-283887.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-283897.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-283907.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionCRITICALCVE-2026-317899.88.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-119: Improper Restriction of Operations within the Bounds of a Memory BufferHIGHCVE-2026-317907.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-321677.86.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')MEDIUMCVE-2026-321754.33.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-321767.86.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')HIGHCVE-2026-321777.36.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementHIGHCVE-2026-321787.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-322037.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-331167.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-331208.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-822: Untrusted Pointer DereferenceHIGHCVE-2026-341807.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-341817.46.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationCRITICALCVE-2026-341829.17.9CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-287: Improper AuthenticationHIGHCVE-2026-341837.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-3518854.4CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-354337.36.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementHIGHCVE-2026-403708.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-73: External Control of File Name or PathHIGHCVE-2026-427647.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-427657.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-427665.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-427675.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionLOWCVE-2026-427683.73.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-427695.34.6CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorLOWCVE-2026-427703.73.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-427716.25.4CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-427894.84.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C7CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:NCWE-295: Improper Certificate ValidationHIGHCVE-2026-427908.17CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C7.6CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:NCWE-295: Improper Certificate ValidationHIGHCVE-2026-428997.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-454457.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-454464.84.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2026-454478.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-287: Improper AuthenticationHIGHCVE-2026-454907.86.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementMEDIUMCVE-2026-454915.54.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-455917.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource Consumption
Tenable has released Tenable Identity Exposure version 3.93.5 to address these issues. The installation files can be obtained from the Tenable Downloads Portal: https://www.tenable.com/downloads/identity-exposure | high | |
| CVE-2026-341837 | Tenable Identity Exposure leverages third-party software to help provide underlying functionality. Several of the third-party components (.NET Windows Server Hosting, NodeJS, Erlang OTP, SQL Server, OpenSSL, Curl) were found to contain vulnerabilities, and updated versions have been made available by the providers.Out of caution and in line with best practice, Tenable has opted to upgrade these components to address the potential impact of the issues. Tenable Identity Exposure version 3.93.5 updates .NET Windows Server Hosting to version 8.0.28.26269, NodeJS to version 20.20.2.0, Erlang OTP to version 26.2.5.21, SQL Server to version 15.0.4470.1, OpenSSL to version 4.0.1, and Curl to version 8.19.0 to address the identified vulnerabilities.Tenable Identity Exposure version v3.93.5 also resolves a vulnerability related to API endpoints returning information to unauthenticated GET requests (CVE-2026-13007).
p.subtitle { display: none; }
table { border-collapse: collapse; width: 100%; }
th { background: #1a1a2e; color: #fff; padding: 8px 10px; text-align: left; font-size: 12px; letter-spacing: 0.04em; white-space: nowrap; }
td { padding: 6px 10px; border-bottom: 1px solid #e5e7eb; vertical-align: top; }
tr:hover td { background: #f5f7ff; }
.cve-id { white-space: nowrap; }
.vector { font-size: 11px; color: #444; word-break: break-all; }
.score { font-weight: 600; white-space: nowrap; }
.lozenge.critical { color: #fff; }
.critical { color: #b91c1c; }
.high { color: #c2410c; }
.medium { color: #b45309; }
.low { color: #15803d; }
.badge { display: inline-block; padding: 1px 6px; border-radius: 3px; font-size: 11px; font-weight: 600; margin-right: 4px; }
.badge.critical { background: #fee2e2; color: #991b1b; }
.badge.high { background: #ffedd5; color: #9a3412; }
.badge.medium { background: #fef9c3; color: #854d0e; }
.badge.low { background: #dcfce7; color: #166534; }
.cwe { font-size: 12px; }
.empty { color: #aaa; }
.new-row td { background: #f0fdf4; }
.new-row:hover td { background: #dcfce7; }
CVE IDBase ScoreTemporal ScoreCVSSv3 VectorCVSSv4 Base ScoreCVSSv4 VectorCWEMEDIUMCVE-2025-111876.15.3CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H/E:U/RL:O/RC:C——CWE-121: Stack-based Buffer OverflowMEDIUMCVE-2025-130345.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-345: Insufficient Verification of Data AuthenticityMEDIUMCVE-2025-140176.35.5CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-416: Use After FreeMEDIUMCVE-2025-145245.34.6CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2025-148195.34.6CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2025-150795.34.6CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorLOWCVE-2025-152243.12.7CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2025-154678.87.6CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-416: Use After FreeMEDIUMCVE-2025-154685.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-154695.54.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlCRITICALCVE-2025-551309.17.9CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-287: Improper AuthenticationHIGHCVE-2025-551317.16.2CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')MEDIUMCVE-2025-551325.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C4.8CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:NCWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2025-552477.36.3CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementMEDIUMCVE-2025-552485.75CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorCRITICALCVE-2025-553159.98.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')HIGHCVE-2025-594657.56.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2025-594667.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-661995.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-681604.74.1CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-6941843.5CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2025-694197.46.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2025-694207.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2025-694217.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-19656.55.7CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlMEDIUMCVE-2026-26736.55.7CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:U/RL:O/RC:C——CWE-284: Improper Access ControlMEDIUMCVE-2026-37835.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-37846.55.7CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-38057.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-48735.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-55456.55.7CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-57737.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-62535.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-62767.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-64295.34.6CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-70095.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-71685.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-73838.17CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2026-90767.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-130077.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:NCWE-306: Missing Authentication for Critical Function; CWE-524: Use of Cache Containing Sensitive InformationHIGHCVE-2026-212187.56.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:NCWE-284: Improper Access ControlHIGHCVE-2026-212628.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-216377.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-217107.56.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-217135.95.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-217145.34.6CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionLOWCVE-2026-217153.32.9CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorLOWCVE-2026-217163.32.9CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlMEDIUMCVE-2026-217175.95.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-227955.54.8CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-227965.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-261307.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-261717.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-283867.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-125: Out-of-bounds ReadHIGHCVE-2026-283878.17CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2026-283887.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-283897.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-283907.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionCRITICALCVE-2026-317899.88.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-119: Improper Restriction of Operations within the Bounds of a Memory BufferHIGHCVE-2026-317907.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-321677.86.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')MEDIUMCVE-2026-321754.33.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-321767.86.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')HIGHCVE-2026-321777.36.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementHIGHCVE-2026-321787.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-322037.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-331167.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-331208.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-822: Untrusted Pointer DereferenceHIGHCVE-2026-341807.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-341817.46.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationCRITICALCVE-2026-341829.17.9CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-287: Improper AuthenticationHIGHCVE-2026-341837.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-3518854.4CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-354337.36.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementHIGHCVE-2026-403708.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-73: External Control of File Name or PathHIGHCVE-2026-427647.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-427657.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-427665.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-427675.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionLOWCVE-2026-427683.73.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-427695.34.6CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorLOWCVE-2026-427703.73.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-427716.25.4CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-427894.84.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C7CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:NCWE-295: Improper Certificate ValidationHIGHCVE-2026-427908.17CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C7.6CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:NCWE-295: Improper Certificate ValidationHIGHCVE-2026-428997.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-454457.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-454464.84.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2026-454478.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-287: Improper AuthenticationHIGHCVE-2026-454907.86.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementMEDIUMCVE-2026-454915.54.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-455917.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource Consumption
Tenable has released Tenable Identity Exposure version 3.93.5 to address these issues. The installation files can be obtained from the Tenable Downloads Portal: https://www.tenable.com/downloads/identity-exposure | high | |
| CVE-2026-354337 | Tenable Identity Exposure leverages third-party software to help provide underlying functionality. Several of the third-party components (.NET Windows Server Hosting, NodeJS, Erlang OTP, SQL Server, OpenSSL, Curl) were found to contain vulnerabilities, and updated versions have been made available by the providers.Out of caution and in line with best practice, Tenable has opted to upgrade these components to address the potential impact of the issues. Tenable Identity Exposure version 3.93.5 updates .NET Windows Server Hosting to version 8.0.28.26269, NodeJS to version 20.20.2.0, Erlang OTP to version 26.2.5.21, SQL Server to version 15.0.4470.1, OpenSSL to version 4.0.1, and Curl to version 8.19.0 to address the identified vulnerabilities.Tenable Identity Exposure version v3.93.5 also resolves a vulnerability related to API endpoints returning information to unauthenticated GET requests (CVE-2026-13007).
p.subtitle { display: none; }
table { border-collapse: collapse; width: 100%; }
th { background: #1a1a2e; color: #fff; padding: 8px 10px; text-align: left; font-size: 12px; letter-spacing: 0.04em; white-space: nowrap; }
td { padding: 6px 10px; border-bottom: 1px solid #e5e7eb; vertical-align: top; }
tr:hover td { background: #f5f7ff; }
.cve-id { white-space: nowrap; }
.vector { font-size: 11px; color: #444; word-break: break-all; }
.score { font-weight: 600; white-space: nowrap; }
.lozenge.critical { color: #fff; }
.critical { color: #b91c1c; }
.high { color: #c2410c; }
.medium { color: #b45309; }
.low { color: #15803d; }
.badge { display: inline-block; padding: 1px 6px; border-radius: 3px; font-size: 11px; font-weight: 600; margin-right: 4px; }
.badge.critical { background: #fee2e2; color: #991b1b; }
.badge.high { background: #ffedd5; color: #9a3412; }
.badge.medium { background: #fef9c3; color: #854d0e; }
.badge.low { background: #dcfce7; color: #166534; }
.cwe { font-size: 12px; }
.empty { color: #aaa; }
.new-row td { background: #f0fdf4; }
.new-row:hover td { background: #dcfce7; }
CVE IDBase ScoreTemporal ScoreCVSSv3 VectorCVSSv4 Base ScoreCVSSv4 VectorCWEMEDIUMCVE-2025-111876.15.3CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H/E:U/RL:O/RC:C——CWE-121: Stack-based Buffer OverflowMEDIUMCVE-2025-130345.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-345: Insufficient Verification of Data AuthenticityMEDIUMCVE-2025-140176.35.5CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-416: Use After FreeMEDIUMCVE-2025-145245.34.6CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2025-148195.34.6CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2025-150795.34.6CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorLOWCVE-2025-152243.12.7CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2025-154678.87.6CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-416: Use After FreeMEDIUMCVE-2025-154685.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-154695.54.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlCRITICALCVE-2025-551309.17.9CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-287: Improper AuthenticationHIGHCVE-2025-551317.16.2CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')MEDIUMCVE-2025-551325.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C4.8CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:NCWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2025-552477.36.3CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementMEDIUMCVE-2025-552485.75CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorCRITICALCVE-2025-553159.98.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')HIGHCVE-2025-594657.56.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2025-594667.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-661995.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-681604.74.1CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-6941843.5CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2025-694197.46.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2025-694207.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2025-694217.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-19656.55.7CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlMEDIUMCVE-2026-26736.55.7CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:U/RL:O/RC:C——CWE-284: Improper Access ControlMEDIUMCVE-2026-37835.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-37846.55.7CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-38057.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-48735.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-55456.55.7CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-57737.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-62535.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-62767.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-64295.34.6CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-70095.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-71685.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-73838.17CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2026-90767.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-130077.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:NCWE-306: Missing Authentication for Critical Function; CWE-524: Use of Cache Containing Sensitive InformationHIGHCVE-2026-212187.56.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:NCWE-284: Improper Access ControlHIGHCVE-2026-212628.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-216377.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-217107.56.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-217135.95.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-217145.34.6CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionLOWCVE-2026-217153.32.9CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorLOWCVE-2026-217163.32.9CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlMEDIUMCVE-2026-217175.95.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-227955.54.8CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-227965.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-261307.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-261717.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-283867.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-125: Out-of-bounds ReadHIGHCVE-2026-283878.17CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2026-283887.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-283897.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-283907.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionCRITICALCVE-2026-317899.88.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-119: Improper Restriction of Operations within the Bounds of a Memory BufferHIGHCVE-2026-317907.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-321677.86.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')MEDIUMCVE-2026-321754.33.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-321767.86.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')HIGHCVE-2026-321777.36.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementHIGHCVE-2026-321787.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-322037.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-331167.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-331208.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-822: Untrusted Pointer DereferenceHIGHCVE-2026-341807.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-341817.46.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationCRITICALCVE-2026-341829.17.9CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-287: Improper AuthenticationHIGHCVE-2026-341837.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-3518854.4CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-354337.36.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementHIGHCVE-2026-403708.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-73: External Control of File Name or PathHIGHCVE-2026-427647.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-427657.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-427665.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-427675.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionLOWCVE-2026-427683.73.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-427695.34.6CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorLOWCVE-2026-427703.73.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-427716.25.4CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-427894.84.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C7CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:NCWE-295: Improper Certificate ValidationHIGHCVE-2026-427908.17CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C7.6CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:NCWE-295: Improper Certificate ValidationHIGHCVE-2026-428997.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-454457.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-454464.84.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2026-454478.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-287: Improper AuthenticationHIGHCVE-2026-454907.86.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementMEDIUMCVE-2026-454915.54.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-455917.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource Consumption
Tenable has released Tenable Identity Exposure version 3.93.5 to address these issues. The installation files can be obtained from the Tenable Downloads Portal: https://www.tenable.com/downloads/identity-exposure | high | |
| CVE-2026-427665 | Tenable Identity Exposure leverages third-party software to help provide underlying functionality. Several of the third-party components (.NET Windows Server Hosting, NodeJS, Erlang OTP, SQL Server, OpenSSL, Curl) were found to contain vulnerabilities, and updated versions have been made available by the providers.Out of caution and in line with best practice, Tenable has opted to upgrade these components to address the potential impact of the issues. Tenable Identity Exposure version 3.93.5 updates .NET Windows Server Hosting to version 8.0.28.26269, NodeJS to version 20.20.2.0, Erlang OTP to version 26.2.5.21, SQL Server to version 15.0.4470.1, OpenSSL to version 4.0.1, and Curl to version 8.19.0 to address the identified vulnerabilities.Tenable Identity Exposure version v3.93.5 also resolves a vulnerability related to API endpoints returning information to unauthenticated GET requests (CVE-2026-13007).
p.subtitle { display: none; }
table { border-collapse: collapse; width: 100%; }
th { background: #1a1a2e; color: #fff; padding: 8px 10px; text-align: left; font-size: 12px; letter-spacing: 0.04em; white-space: nowrap; }
td { padding: 6px 10px; border-bottom: 1px solid #e5e7eb; vertical-align: top; }
tr:hover td { background: #f5f7ff; }
.cve-id { white-space: nowrap; }
.vector { font-size: 11px; color: #444; word-break: break-all; }
.score { font-weight: 600; white-space: nowrap; }
.lozenge.critical { color: #fff; }
.critical { color: #b91c1c; }
.high { color: #c2410c; }
.medium { color: #b45309; }
.low { color: #15803d; }
.badge { display: inline-block; padding: 1px 6px; border-radius: 3px; font-size: 11px; font-weight: 600; margin-right: 4px; }
.badge.critical { background: #fee2e2; color: #991b1b; }
.badge.high { background: #ffedd5; color: #9a3412; }
.badge.medium { background: #fef9c3; color: #854d0e; }
.badge.low { background: #dcfce7; color: #166534; }
.cwe { font-size: 12px; }
.empty { color: #aaa; }
.new-row td { background: #f0fdf4; }
.new-row:hover td { background: #dcfce7; }
CVE IDBase ScoreTemporal ScoreCVSSv3 VectorCVSSv4 Base ScoreCVSSv4 VectorCWEMEDIUMCVE-2025-111876.15.3CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H/E:U/RL:O/RC:C——CWE-121: Stack-based Buffer OverflowMEDIUMCVE-2025-130345.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-345: Insufficient Verification of Data AuthenticityMEDIUMCVE-2025-140176.35.5CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-416: Use After FreeMEDIUMCVE-2025-145245.34.6CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2025-148195.34.6CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2025-150795.34.6CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorLOWCVE-2025-152243.12.7CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2025-154678.87.6CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-416: Use After FreeMEDIUMCVE-2025-154685.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-154695.54.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlCRITICALCVE-2025-551309.17.9CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-287: Improper AuthenticationHIGHCVE-2025-551317.16.2CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')MEDIUMCVE-2025-551325.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C4.8CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:NCWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2025-552477.36.3CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementMEDIUMCVE-2025-552485.75CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorCRITICALCVE-2025-553159.98.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')HIGHCVE-2025-594657.56.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2025-594667.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-661995.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-681604.74.1CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-6941843.5CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2025-694197.46.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2025-694207.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2025-694217.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-19656.55.7CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlMEDIUMCVE-2026-26736.55.7CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:U/RL:O/RC:C——CWE-284: Improper Access ControlMEDIUMCVE-2026-37835.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-37846.55.7CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-38057.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-48735.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-55456.55.7CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-57737.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-62535.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-62767.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-64295.34.6CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-70095.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-71685.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-73838.17CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2026-90767.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-130077.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:NCWE-306: Missing Authentication for Critical Function; CWE-524: Use of Cache Containing Sensitive InformationHIGHCVE-2026-212187.56.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:NCWE-284: Improper Access ControlHIGHCVE-2026-212628.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-216377.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-217107.56.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-217135.95.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-217145.34.6CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionLOWCVE-2026-217153.32.9CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorLOWCVE-2026-217163.32.9CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlMEDIUMCVE-2026-217175.95.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-227955.54.8CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-227965.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-261307.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-261717.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-283867.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-125: Out-of-bounds ReadHIGHCVE-2026-283878.17CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2026-283887.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-283897.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-283907.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionCRITICALCVE-2026-317899.88.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-119: Improper Restriction of Operations within the Bounds of a Memory BufferHIGHCVE-2026-317907.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-321677.86.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')MEDIUMCVE-2026-321754.33.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-321767.86.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')HIGHCVE-2026-321777.36.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementHIGHCVE-2026-321787.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-322037.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-331167.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-331208.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-822: Untrusted Pointer DereferenceHIGHCVE-2026-341807.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-341817.46.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationCRITICALCVE-2026-341829.17.9CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-287: Improper AuthenticationHIGHCVE-2026-341837.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-3518854.4CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-354337.36.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementHIGHCVE-2026-403708.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-73: External Control of File Name or PathHIGHCVE-2026-427647.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-427657.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-427665.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-427675.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionLOWCVE-2026-427683.73.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-427695.34.6CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorLOWCVE-2026-427703.73.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-427716.25.4CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-427894.84.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C7CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:NCWE-295: Improper Certificate ValidationHIGHCVE-2026-427908.17CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C7.6CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:NCWE-295: Improper Certificate ValidationHIGHCVE-2026-428997.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-454457.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-454464.84.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2026-454478.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-287: Improper AuthenticationHIGHCVE-2026-454907.86.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementMEDIUMCVE-2026-454915.54.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-455917.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource Consumption
Tenable has released Tenable Identity Exposure version 3.93.5 to address these issues. The installation files can be obtained from the Tenable Downloads Portal: https://www.tenable.com/downloads/identity-exposure | high | |
| CVE-2026-427695 | Tenable Identity Exposure leverages third-party software to help provide underlying functionality. Several of the third-party components (.NET Windows Server Hosting, NodeJS, Erlang OTP, SQL Server, OpenSSL, Curl) were found to contain vulnerabilities, and updated versions have been made available by the providers.Out of caution and in line with best practice, Tenable has opted to upgrade these components to address the potential impact of the issues. Tenable Identity Exposure version 3.93.5 updates .NET Windows Server Hosting to version 8.0.28.26269, NodeJS to version 20.20.2.0, Erlang OTP to version 26.2.5.21, SQL Server to version 15.0.4470.1, OpenSSL to version 4.0.1, and Curl to version 8.19.0 to address the identified vulnerabilities.Tenable Identity Exposure version v3.93.5 also resolves a vulnerability related to API endpoints returning information to unauthenticated GET requests (CVE-2026-13007).
p.subtitle { display: none; }
table { border-collapse: collapse; width: 100%; }
th { background: #1a1a2e; color: #fff; padding: 8px 10px; text-align: left; font-size: 12px; letter-spacing: 0.04em; white-space: nowrap; }
td { padding: 6px 10px; border-bottom: 1px solid #e5e7eb; vertical-align: top; }
tr:hover td { background: #f5f7ff; }
.cve-id { white-space: nowrap; }
.vector { font-size: 11px; color: #444; word-break: break-all; }
.score { font-weight: 600; white-space: nowrap; }
.lozenge.critical { color: #fff; }
.critical { color: #b91c1c; }
.high { color: #c2410c; }
.medium { color: #b45309; }
.low { color: #15803d; }
.badge { display: inline-block; padding: 1px 6px; border-radius: 3px; font-size: 11px; font-weight: 600; margin-right: 4px; }
.badge.critical { background: #fee2e2; color: #991b1b; }
.badge.high { background: #ffedd5; color: #9a3412; }
.badge.medium { background: #fef9c3; color: #854d0e; }
.badge.low { background: #dcfce7; color: #166534; }
.cwe { font-size: 12px; }
.empty { color: #aaa; }
.new-row td { background: #f0fdf4; }
.new-row:hover td { background: #dcfce7; }
CVE IDBase ScoreTemporal ScoreCVSSv3 VectorCVSSv4 Base ScoreCVSSv4 VectorCWEMEDIUMCVE-2025-111876.15.3CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H/E:U/RL:O/RC:C——CWE-121: Stack-based Buffer OverflowMEDIUMCVE-2025-130345.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-345: Insufficient Verification of Data AuthenticityMEDIUMCVE-2025-140176.35.5CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-416: Use After FreeMEDIUMCVE-2025-145245.34.6CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2025-148195.34.6CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2025-150795.34.6CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorLOWCVE-2025-152243.12.7CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2025-154678.87.6CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-416: Use After FreeMEDIUMCVE-2025-154685.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-154695.54.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlCRITICALCVE-2025-551309.17.9CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-287: Improper AuthenticationHIGHCVE-2025-551317.16.2CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')MEDIUMCVE-2025-551325.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C4.8CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:NCWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2025-552477.36.3CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementMEDIUMCVE-2025-552485.75CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorCRITICALCVE-2025-553159.98.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')HIGHCVE-2025-594657.56.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2025-594667.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-661995.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-681604.74.1CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2025-6941843.5CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2025-694197.46.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2025-694207.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2025-694217.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-19656.55.7CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlMEDIUMCVE-2026-26736.55.7CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:U/RL:O/RC:C——CWE-284: Improper Access ControlMEDIUMCVE-2026-37835.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-37846.55.7CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-38057.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-48735.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-55456.55.7CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-57737.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-62535.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-62767.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-64295.34.6CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-70095.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-71685.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-73838.17CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2026-90767.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-130077.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:NCWE-306: Missing Authentication for Critical Function; CWE-524: Use of Cache Containing Sensitive InformationHIGHCVE-2026-212187.56.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:NCWE-284: Improper Access ControlHIGHCVE-2026-212628.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-216377.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-217107.56.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-217135.95.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-217145.34.6CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionLOWCVE-2026-217153.32.9CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorLOWCVE-2026-217163.32.9CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlMEDIUMCVE-2026-217175.95.1CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-227955.54.8CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-227965.34.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-261307.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-261717.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-283867.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-125: Out-of-bounds ReadHIGHCVE-2026-283878.17CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2026-283887.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-283897.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-283907.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionCRITICALCVE-2026-317899.88.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-119: Improper Restriction of Operations within the Bounds of a Memory BufferHIGHCVE-2026-317907.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-321677.86.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')MEDIUMCVE-2026-321754.33.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-321767.86.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')HIGHCVE-2026-321777.36.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementHIGHCVE-2026-321787.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-322037.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-331167.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-331208.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-822: Untrusted Pointer DereferenceHIGHCVE-2026-341807.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-341817.46.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationCRITICALCVE-2026-341829.17.9CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C——CWE-287: Improper AuthenticationHIGHCVE-2026-341837.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-3518854.4CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorHIGHCVE-2026-354337.36.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementHIGHCVE-2026-403708.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-73: External Control of File Name or PathHIGHCVE-2026-427647.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-427657.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-427665.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-427675.95.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionLOWCVE-2026-427683.73.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-427695.34.6CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorLOWCVE-2026-427703.73.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-427716.25.4CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionMEDIUMCVE-2026-427894.84.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C7CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:NCWE-295: Improper Certificate ValidationHIGHCVE-2026-427908.17CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C7.6CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:NCWE-295: Improper Certificate ValidationHIGHCVE-2026-428997.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource ConsumptionHIGHCVE-2026-454457.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C——CWE-200: Exposure of Sensitive Information to an Unauthorized ActorMEDIUMCVE-2026-454464.84.2CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C——CWE-295: Improper Certificate ValidationHIGHCVE-2026-454478.87.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-287: Improper AuthenticationHIGHCVE-2026-454907.86.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C——CWE-269: Improper Privilege ManagementMEDIUMCVE-2026-454915.54.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C——CWE-284: Improper Access ControlHIGHCVE-2026-455917.56.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C——CWE-400: Uncontrolled Resource Consumption
Tenable has released Tenable Identity Exposure version 3.93.5 to address these issues. The installation files can be obtained from the Tenable Downloads Portal: https://www.tenable.com/downloads/identity-exposure | high | |
| CVE-2026-19546 | A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed Statement, Description and Mitigation please reffer to the original https://access.redhat.com/security/cve/cve-2026-19546. | high | |
| CVE-2026-42016 | JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope. | high | |
| CVE-2026-3136 | An improper authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-1-26 allows a remote attacker to execute arbitrary code in the build environment. This vulnerability was patched on 26 January 2026, and no customer action is needed. | high | |
| CVE-2026-58096 | LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersized options would trigger an out-of-bounds write. A malicious PPP peer can exploit CVE-2026-58095 and CVE-2026-58096 to crash ppp(8) or potentially execute arbitrary code as root. | high | |
| CVE-2026-10797 | CVE-2026-10797 is a CVE assigned to cover a UEFI shim bootloader security feature bypass. | No Score | |
| CVE-2026-94301 | The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committed to the 2.2.X branch only. The 2.0.X and 2.1.X maintenance branches never received the resolveProxyClass() override, so the 2.0.29 and 2.1.13 artifacts listed as fixed -- and every later release on those lines, up to and including the current 2.0.30 and 2.1.14 -- remain vulnerable to the exact allow-list bypass that CVE-2026-47065 was meant to close. | critical | |
| CVE-2026-34990 | OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, a local unprivileged user can coerce cupsd into authenticating to an attacker-controlled localhost IPP service with a reusable Authorization: Local ... token. That token is enough to drive /admin/ requests on localhost, and the attacker can combine CUPS-Create-Local-Printer with printer-is-shared=true to persist a file:///... queue even though the normal FileDevice policy rejects such URIs. Printing to that queue gives an arbitrary root file overwrite; the PoC below uses that primitive to drop a sudoers fragment and demonstrate root command execution. At time of publication, there are no publicly available patches. | medium | |
| CVE-2026-44599 | Tor before 0.4.9.7 can attempt or accept BEGIN_DIR via conflux legs, aka TROVE-2026-008. | medium | |
| CVE-2026-22020 | Red Hat Enterprise Linux - libpng: Update LibPNG (Oracle CPU 2026-04)
Ubuntu Linux - [updated libpng in Oracle Java] | critical | |
| CVE-2026-61612 | CKAN MCP Server is a tool for querying CKAN open data portals. Prior to version 0.4.108, the SSRF guard `validateServerUrl` (added for CVE-2026-33060, extended for CVE-2026-53509) validates only the hostname string and never resolves DNS. Any caller-supplied `server_url` whose hostname *resolves* to an internal address passes the guard, so the server issues requests to loopback and cloud metadata (`169.254.169.254`). This is a third bypass of the same guard, and it reaches IMDS — strictly more than CVE-2026-53509, which only reached loopback. Version 0.4.108 contains an updated fix. | medium | |
| CVE-2026-21016 | Incorrect privilege assignment in LocationManager prior to SMR May-2026 Release 1 allows local attackers to access sensitive information. | medium | |
| CVE-2026-21025 | Incorrect privilege assignment in Telephony prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information. | medium | |
| CVE-2026-21050 | Improper access control in SmartThingsKit prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information. | medium | |
| CVE-2026-21064 | Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability. | high | |
| CVE-2026-19410 | An Incorrect Authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-06-24 on Google Cloud Platform allows a remote attacker to execute unreviewed code in the build environment using webhook suppression. This vulnerability was patched on 24 June 2026, and no customer action is needed. | critical | |
| CVE-2026-67276 | RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key.This issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable) | critical | |
| CVE-2026-62643 | In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. NOTE: this issue exists because of insufficient fixes for CVE-2026-35540 and CVE-2026-48843. | critical | |
| CVE-2026-18577 | An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1 | high | |
| CVE-2026-12715 | Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an attacker to download other users' deployed source code and access sensitive data via unauthorized GCS URL signing requests. This vulnerability was patched on 15 April 2026, and no customer action is needed. | high | |
| CVE-2026-19486 | A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default service account access token. This vulnerability was patched on 01 June 2026. Users will need to redeploy their previously deployed apps. | high | |
| CVE-2026-21047 | Out-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allows remote attackers to potentially execute arbitrary code. | high | |
| CVE-2026-21017 | Improper handling of insufficient privileges in SecTelephonyProvider prior to SMR Jun-2026 Release 1 allows local attackers to access privileged files. | medium | |
| CVE-2026-21040 | Improper access control in IAFDService prior to SMR Jul-2026 Release 1 allows local privileged attackers to use the privileged APIs. | medium | |
| CVE-2026-21066 | Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. | medium | |
| CVE-2026-21068 | Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code. | high | |
| CVE-2026-34204 | MinIO is a high-performance object storage system. Prior to version RELEASE.2026-03-26T21-24-40Z, a flaw in extractMetadataFromMime() allows any authenticated user with s3:PutObject permission to inject internal server-side encryption metadata into objects by sending crafted X-Minio-Replication-* headers on a normal PutObject request. This issue has been patched in version RELEASE.2026-03-26T21-24-40Z. | high | |
| CVE-2026-21042 | Out-of-bounds write in libsavsac.so prior to SMR Jul-2026 Release 1 allows remote attackers to execute arbitrary code. | high | |
| CVE-2026-40217 | LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI. | high | |
| CVE-2026-2244 | A vulnerability in Google Cloud Vertex AI Workbench from 7/21/2025 to 01/30/2026 allows an attacker to exfiltrate valid Google Cloud access tokens of other users via abuse of a built-in startup script. All instances after January 30th, 2026 have been patched to protect from this vulnerability. No user action is required for this. | high | |
| CVE-2026-34980 | OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, in a network-exposed cupsd with a shared target queue, an unauthorized client can send a Print-Job to that shared PostScript queue without authentication. The server accepts a page-border value supplied as textWithoutLanguage, preserves an embedded newline through option escaping and reparse, and then reparses the resulting second-line PPD: text as a trusted scheduler control record. A follow-up raw print job can therefore make the server execute an attacker-chosen existing binary such as /usr/bin/vim as lp. At time of publication, there are no publicly available patches. | medium | |
| CVE-2026-57913 | Johnson & Johnson Audit Tracking Management System (ATMS) before 2026-04-21 allows viewing of meeting minutes and transcripts. | high | |
| CVE-2026-21086 | Improper authorization in ProxyHandler prior to SMR Aug-2026 Release 1 allows local attackers to access proxy configuration. | medium | |
| CVE-2026-54683 | NL Portal Backend Libraries: Document contents remained downloadable by any logged-in user (incomplete fix of CVE-2026-49463) | medium | |
| CVE-2026-21015 | Incorrect default permissions in FactoryCamera prior to SMR May-2026 Release 1 allows local attacker to access unique identifier. | medium | |
| CVE-2026-21041 | Improper access control in SamsungSEAgentService prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information. | medium | |
| CVE-2026-44600 | Tor before 0.4.9.7 mishandles accounting of the conflux out-of-order queue during the clearing of a queue, aka TROVE-2026-010. | medium | |
| CVE-2026-21011 | Incorrect privilege assignment in Bluetooth in Maintenance mode prior to SMR Apr-2026 Release 1 allows physical attackers to bypass Extend Unlock. | medium | |
| CVE-2026-20978 | Improper authorization in KnoxGuardManager prior to SMR Feb-2026 Release 1 allows local attackers to bypass the persistence configuration of the application. | medium | |
| CVE-2026-21104 | Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code. | high | |