Low-Priv Users Can Run Admin Commands in Tenable Identity Exposure via CVE-2026-106126
A critical vulnerability in Tenable’s SaaS identity platform lets low-privilege users run arbitrary commands as the system administrator.
Key points
- CVE-2026-106126 is rated critical with a CVSS score of 9.9
- The flaw enables command injection within the Active Directory Events Listener
- Authentication is required, but low-privilege access is sufficient for exploitation
Tenable has identified a severe command injection vulnerability in its Identity Exposure SaaS product that grants attackers full system control. The flaw affects versions prior to 3.126.0 and requires only an authenticated account with minimal privileges to exploit.
What happened
According to the National Vulnerability Database (NVD), the vulnerability, tracked as CVE-2026-106126, resides in the Active Directory Events Listener component of Tenable Identity Exposure. This weakness is categorized under CWE-78, indicating improper neutralization of special elements used in an OS command. An attacker who has gained an authenticated, low-privileged user session can inject arbitrary commands into this listener. The result is the execution of these commands with SYSTEM privileges on the Primary Domain Controller emulator (PDCe). This elevation of privilege allows the attacker to operate with the highest level of authority within the affected environment. The issue affects all versions of Tenable Identity Exposure SaaS before version 3.126.0.
Why it matters
The impact of this vulnerability is severe for organizations relying on Tenable Identity Exposure for security monitoring and identity management. Because the exploitation path leads to SYSTEM-level execution, a successful attack compromises the integrity of the underlying infrastructure. Even though the attacker must first authenticate, the low privilege requirement makes this a realistic threat vector. Low-privilege accounts are often more numerous and potentially less scrutinized than high-privilege administrative accounts. Consequently, the attack surface is broader than it would be if only admin accounts were vulnerable. The CVSS score of 9.9 reflects the maximum severity of this issue, highlighting the potential for total system takeover. For IT managers, this represents a critical failure in the boundary between user actions and system-level operations.
What to watch
- Monitor for unusual command executions or process launches on systems integrated with Tenable Identity Exposure
- Review authentication logs for low-privilege accounts exhibiting anomalous activity patterns
- Verify current software versions against the patched baseline of 3.126.0 or later
- Assess the security posture of the Active Directory Events Listener configurations
What to do and how to stay safe: Tenable
- Audit all user accounts with access to the Identity Exposure platform to identify and restrict low-privilege roles where possible
- Implement strict monitoring and alerting for any command execution attempts originating from the Active Directory Events Listener
- Ensure that network segmentation isolates the PDCe from direct exposure to potential injection payloads from the SaaS interface
- Once the vendor provides an update, apply version 3.126.0 or later immediately to remediate the vulnerability
General security guidance from the Patch Gazette newsroom. It is not confirmed advice from the organisations named in this story.
Frequently asked questions
What is CVE-2026-106126?
It is a critical command injection vulnerability in the Active Directory Events Listener of Tenable Identity Exposure that allows arbitrary command execution as SYSTEM.
Do attackers need admin rights to exploit this flaw?
No, the vulnerability allows an authenticated, low-privileged attacker to execute commands with SYSTEM privileges.
Which versions of Tenable Identity Exposure are affected?
All versions of Tenable Identity Exposure SaaS before version 3.126.0 are affected by this vulnerability.




