Description
A command injection vulnerability in the Active Directory Events Listener of Tenable Identity Exposure (SaaS) allows an authenticated, low-privileged attacker to execute arbitrary commands as SYSTEM on the PDCe.
Published: 2026-10-08
Score: 9.4 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is a command injection flaw in the Active Directory Events Listener component of Tenable Identity Exposure (SaaS). An authenticated user with low privileges can inject and execute arbitrary operating‑system commands with SYSTEM rights on the PDCe, effectively granting remote code execution to the attacker. The flaw is classified as CWE-78.

Affected Systems

Affected deployments are Tenable’s Identity Exposure SaaS offering, specifically the Active Directory Events Listener. No specific version numbers are supplied by the CNA, so all releases prior to the documented fix are potentially impacted.

Risk and Exploitability

The CVSS base score of 9.4 indicates critical severity. Because the EPSS score is not available, the current exploit probability is uncertain, but the high CVSS and the fact that the flaw allows execution with SYSTEM privileges warrant immediate remediation. The vulnerability requires valid authentication but only a low‑privileged user, reducing the initial barrier and making it likely that attackers with legitimate credentials can exploit it. The flaw is not listed in the CISA KEV catalog as of the latest data.

Generated by OpenCVE AI on October 8, 2026 at 21:29 UTC.

Remediation

Vendor Solution

To fully resolve this issue, existing installations must run Register-TenableIOA.ps1 -Uninstall and reinstall the listener after upgrading. Please see the full release notes for additional instructions. ( https://docs.tenable.com/identity-exposure.htm )


OpenCVE Recommended Actions

  • Run Register-TenableIOA.ps1 -Uninstall to remove the vulnerable Listener component.
  • Upgrade Tenable Identity Exposure to the latest release.
  • Reinstall the Listener after upgrading following the vendor’s instructions.

Generated by OpenCVE AI on October 8, 2026 at 21:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
Description A command injection vulnerability in the Active Directory Events Listener of Tenable Identity Exposure (SaaS) allows an authenticated, low-privileged attacker to execute arbitrary commands as SYSTEM on the PDCe.
Title Command Injection
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published:

Updated: 2026-10-08T20:14:59.908Z

Reserved: 2026-10-06T15:41:52.906Z

Link: CVE-2026-106126

cve-icon Vulnrichment

Updated: 2026-10-08T20:14:56.301Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T20:17:29.950

Modified: 2026-10-08T21:17:51.547

Link: CVE-2026-106126

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T21:30:18Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')