Skip to content
eastbaycyber

CVE-2026-106126: Tenable Identity Exposure

CVSS · Critical
9.9
In CISA KEV
No
Published
Oct 8
CVE explainers 9 min read
Security Research Desk Source-checked
Auto-checked against the official CVE record · Human-reviewed after publishing · Updated 2026-10-08
▲ Escalation ViewOne CVE, briefed at three altitudes — skim the Brief, weigh the Impact, or work the Runbook. The way a SOC actually reads it.
CISOBrief · 30-second brief

TL;DR - CVE-2026-106126 is a CVSS 9.9 command-injection vulnerability in Tenable Identity Exposure SaaS. - An authenticated, low-privileged attacker may execute commands as SYSTEM on the PDCe. - Verify deployment of Tenable Identity Exposure 3.126.0 and investigate suspicious domain-controller activity.

Vulnerability at a Glance

Field Details
CVE ID CVE-2026-106126
Product Tenable Identity Exposure (SaaS)
Vulnerable component Active Directory Events Listener
CVSS base score 9.9 Critical
CVSS vector Not included in the supplied NVD data; consult Tenable’s advisory for the authoritative vector
Attack vector Not specified in the supplied sources
Authentication or privileges Authenticated, low-privileged user
Impact Arbitrary command execution as SYSTEM on the PDCe
Patch available Yes
Fixed version Tenable Identity Exposure 3.126.0 (SaaS)
CISA KEV status Not listed

CVE-2026-106126 affects the Active Directory Events Listener in Tenable Identity Exposure SaaS. The reported consequence is particularly serious because exploitation may allow a low-privileged authenticated account to execute arbitrary commands in the SYSTEM security context on the domain controller holding the Primary Domain Controller Emulator role.

The available information does not include the complete CVSS vector or an explicit vulnerable-version range. Administrators should not treat those missing fields as evidence of reduced exposure. If a tenant uses the affected product and its deployed version cannot be verified, treat it as requiring remediation until Tenable confirms that the tenant has received the fix.

Analyst’s Take: The first operational question is whether the tenant is running the fixing release, not whether a public exploit exists. The reported path from low-privileged authenticated access to SYSTEM execution on the PDCe warrants containment and telemetry review while SaaS rollout status is being confirmed.

What Is This Vulnerability?

The issue is described as a command-injection vulnerability in the Active Directory Events Listener. Command injection generally occurs when attacker-controlled input reaches an operating-system command interpreter or command execution routine without sufficient separation, validation, or escaping. In this case, the reported impact is arbitrary command execution as SYSTEM on the PDCe.

The supplied advisory and NVD information do not disclose the vulnerable parameter, request path, code function, injection syntax, or exact exploitation sequence. Those details should not be inferred. Defenders should focus on the confirmed security boundary crossing: a low-privileged authenticated user may be able to influence command execution in a component associated with Active Directory monitoring, with execution reaching a highly privileged domain-controller context.

This impact can extend beyond the Tenable deployment itself. SYSTEM-level execution on a PDCe can provide access to sensitive directory data, local credentials, services, scheduled tasks, and other control paths that may support domain compromise. The practical risk depends on the PDCe’s controls and the attacker’s ability to authenticate to and interact with the affected Tenable tenant.

AnalystImpact · assess the risk

Who Is Affected?

The affected product is Tenable Identity Exposure (SaaS), specifically its Active Directory Events Listener component. The supplied NVD record does not identify a vulnerable version range. Tenable identifies version 3.126.0 (SaaS) as fixing the vulnerability.

Deployment question Current answer
Product affected Tenable Identity Exposure (SaaS)
Component affected Active Directory Events Listener
Vulnerable version range Not published in the supplied record
Fixed version 3.126.0
Customer-managed installation Not indicated; the supplied record describes the SaaS product
Required user access Authenticated, low-privileged access

Because this is a SaaS service, customers may not control the underlying software installation or rollout timing. Version numbers may be visible in a tenant console, release information page, support response, or service metadata. If the tenant does not expose a version, request written confirmation from Tenable that the relevant remediation has been deployed.

Organizations that have configured Tenable Identity Exposure to monitor Active Directory should prioritize review even when no administrator account is believed to be exposed. The attack model specifically identifies a low-privileged authenticated user, so access reviews should include service users, delegated operators, contractors, help-desk accounts, and dormant accounts that retain access to the tenant.

CVSS Score Breakdown

CVE-2026-106126 has a published base score of 9.9, rated Critical. For background on how vulnerability scoring works, see what is CVSS?. The supplied NVD response does not include the CVSS vector, so the individual metric values cannot be stated reliably. The available material does not establish whether the official vector classifies the attack as network, adjacent, or local, nor does it provide the exact confidentiality, integrity, availability, scope, or user-interaction metrics.

The known facts still explain why the score is severe. Exploitation reportedly requires authentication but not administrative privileges, and successful exploitation can produce arbitrary command execution under SYSTEM on a PDCe. That combination creates a high-impact path from a relatively weak account to a privileged domain-controller execution context.

CVSS-related fact Assessment
Base score 9.9
Severity Critical
Privileges required Low, based on the supplied vulnerability description
Authentication Required
User interaction Not specified
Attack vector Not specified
Confidentiality, integrity, availability impact Potentially high due to SYSTEM execution on the PDCe, but the official metric values are not supplied
Scope Not specified
Authoritative vector Tenable advisory or complete NVD record

Do not reconstruct a CVSS vector from the prose description. Security teams should use the vendor advisory at https://www.tenable.com/security/tns-2026-27 or the complete NVD record when exact metric-level scoring is required for prioritization or compliance reporting.

Exploitation Status

No confirmed in-the-wild exploitation was identified in the supplied NVD data, Tenable advisory material, or CISA Known Exploited Vulnerabilities lookup. CVE-2026-106126 is also not listed in the CISA KEV catalog as of the supplied assessment.

No public proof of concept, exploit repository, or GitHub reference was identified in the supplied sources. The publication date is 2026-10-08, so the available observation window is limited. Absence of a public PoC or KEV listing does not demonstrate that exploitation is impossible or that the vulnerability has not been used privately.

Question Current status
Confirmed exploitation in the wild? No evidence identified in the supplied sources
Listed in CISA KEV? No
Public PoC identified? No
Exploit details published? Not in the supplied material
Recommended priority High, because of the 9.9 score and potential SYSTEM execution on a PDCe

Treat the vulnerability as a priority remediation item without waiting for exploitation confirmation. An attacker who already possesses a valid low-privileged account may not need a public exploit if the vulnerable functionality is accessible through normal tenant operations.

ResponderRunbook · act now

How to Detect It

Detection should combine Tenable tenant activity with telemetry from the PDCe. Review Tenable audit records for unusual access by low-privileged users, unexpected use of the Active Directory Events Listener, activity outside normal administrative windows, and changes in the tenant’s configuration or monitored-directory integrations. The supplied material does not identify a definitive Tenable-specific event ID or log field, so organizations should obtain the relevant audit schema from Tenable before treating any single event as conclusive.

On the PDCe, look for unusual child processes created by services or agent processes associated with the integration, particularly when those processes run as NT AUTHORITY\SYSTEM. Review Windows Security process-creation events where command-line auditing is enabled, and use Sysmon Event ID 1 if Sysmon is deployed. Correlate process creation with logons, service changes, PowerShell execution, scheduled-task creation, and outbound connections.

Technical Notes

A generic Microsoft Sentinel or Kusto-style query can help identify suspicious SYSTEM process creation on the PDCe. Replace the host and process names with the actual names observed in the environment; the supplied sources do not identify the vulnerable listener’s local process name.

let pdce = "PDCe-HOSTNAME";
SecurityEvent
| where Computer =~ pdce
| where EventID == 4688
| where SubjectUserName endswith "$"
    or SubjectUserName =~ "SYSTEM"
| where NewProcessName has_any (
    "powershell.exe",
    "pwsh.exe",
    "cmd.exe",
    "rundll32.exe",
    "regsvr32.exe",
    "mshta.exe",
    "wscript.exe",
    "cscript.exe"
)
| project TimeGenerated, Computer, SubjectUserName,
          NewProcessName, CommandLine, ParentProcessName
| order by TimeGenerated desc

A useful investigation pattern is a service or monitoring process spawning a command interpreter, followed by directory, credential, persistence, or network activity. This is not a CVE-specific signature and will produce legitimate results in some environments. Validate the parent process, account, command line, timing, and corresponding Tenable audit event before escalating.

For organizations using Windows event forwarding, search for process-creation records with patterns such as:

Event ID: 4688
Computer: <PDCe>
SubjectUserName: SYSTEM
NewProcessName: *\cmd.exe OR *\powershell.exe
ParentProcessName: <unexpected monitoring or integration process>

Also review Event IDs 7045 and 4697 for unexpected service installation, 4698 for scheduled-task creation, and PowerShell operational logs for encoded or obfuscated commands. These events are supporting indicators, not proof that CVE-2026-106126 was exploited.

Mitigation and Patching

Tenable identifies Tenable Identity Exposure version 3.126.0 (SaaS) as the fixing version. Customers should verify that their tenant has received version 3.126.0 or a later Tenable-provided release that includes the same remediation. The supplied information does not provide an earlier affected range, so organizations should not assume that only a narrow set of versions requires review.

SaaS customers generally do not install a package on the PDCe to remediate this issue. Use the tenant’s version or service-status information if available, and open a Tenable Support case when the deployed version or rollout status cannot be confirmed. Record the confirmation, tenant identifier, date of remediation, and any required restart or connector action in the change record.

Access reviews should also cover stored credentials and privileged secrets used by integrations. Organizations formalizing that process can use this secrets management glossary as a reference when reviewing service-account exposure and credential rotation requirements.

Technical Notes

There is no customer-side upgrade command in the supplied advisory, and inventing a Tenable CLI or API endpoint would create operational risk. The actionable upgrade procedure is:

  1. Confirm the tenant’s deployed release in the Tenable Identity Exposure console or service documentation.
  2. Verify that the tenant reports 3.126.0 or later.
  3. If the version is not visible, submit a support request stating: “Please confirm remediation of CVE-2026-106126 and the tenant’s deployed Identity Exposure version.”
  4. Retest the Active Directory integration after Tenable confirms the update.

As a temporary access-control workaround, identify unnecessary accounts with access to the affected tenant and disable or remove that access. For teams reviewing access to multiple security platforms, a business-approved password manager such as Try 1Password → can help centralize credential controls, although it is not a substitute for patching or vendor confirmation.

For an on-premises Active Directory account that no longer requires access, an administrator can use the standard PowerShell cmdlet after validating the account and change approval:

Import-Module ActiveDirectory
Disable-ADAccount -Identity "<account-sAMAccountName>"

This is an account containment measure, not a vendor-confirmed fix. Do not disable service accounts blindly. Where operationally feasible, suspend nonessential low-privilege access to Tenable Identity Exposure, rotate credentials for accounts suspected of misuse, and monitor the PDCe until the SaaS remediation is confirmed.

After patch confirmation, review historical tenant audit data and PDCe telemetry for anomalous process creation, service installation, scheduled tasks, PowerShell activity, unexpected directory changes, and suspicious authentication. If evidence of command execution on the PDCe exists, isolate the host according to the organization’s domain-controller incident-response plan and investigate for credential theft or broader domain compromise.

References

Source Purpose
Tenable security advisory TNS-2026-27 Vendor advisory and fixed-version information
NVD record for CVE-2026-106126 CVE description and vulnerability metadata
CISA Known Exploited Vulnerabilities Catalog Check for later KEV inclusion or exploitation confirmation

Start by confirming the tenant’s deployed version and restricting unnecessary low-privilege access while that check is underway. Because the supplied records do not include the full CVSS vector, an explicit vulnerable-version range, a public exploit, or confirmed exploitation evidence, use Tenable’s advisory and tenant-specific confirmation for the remediation decision. If PDCe telemetry shows suspicious SYSTEM process creation, move directly into domain-controller incident response rather than waiting for public exploitation reporting.

This article may contain affiliate links. We earn a commission on qualifying purchases at no extra cost to you.

Last verified: 2026-10-08

Disclaimer: This article may contain affiliate links. We earn a commission on qualifying purchases at no extra cost to you.