Command Injection Vulnerability in Tenable Identity Exposure
CVE-2026-106126
9.4CRITICAL
What is CVE-2026-106126?
A command injection vulnerability exists in the Active Directory Events Listener of Tenable Identity Exposure (SaaS). This flaw allows an authenticated user with low privileges to execute arbitrary commands with SYSTEM-level access on the Primary Domain Controller Emulator (PDCe), potentially compromising the security of the affected system.
Affected Version(s)
Tenable Identity Exposure (SaaS) Windows 0
