Tenable fixes critical command injection in Identity Exposure SaaS
EditorialBy TrustList Editorial
The fix ships in SaaS 3.126.0, but the Active Directory listener must also be uninstalled and reinstalled before the flaw is closed. Tenable credits an outside researcher.
- Cybersecurity
- Vulnerability Management
- SaaS
About Tenable fixes critical command injection in Identity Exposure SaaS
Tenable fixes critical command injection in Identity Exposure SaaS
8 October 2026: Tenable has fixed CVE-2026-106126, a critical OS command injection flaw (CVSS v3 9.9, CVSS v4 9.4) in the Active Directory Events Listener of Tenable Identity Exposure, in version 3.126.0 of the SaaS service. An attacker who is logged in with only low privileges can run arbitrary commands as SYSTEM on the PDCe, the domain controller that holds the primary domain controller emulator role. The advisory, TNS-2026-27, rates the risk factor critical and does not say the flaw has been exploited.
Not yet independently verified. Based on Tenable's advisory only. The advisory does not say whether the flaw has been exploited, and it carries no last-updated date. We will update this when it can be confirmed, and remove this note.
The weakness is classed as CWE-78. The CVSS v3 vector shows a network attack with low complexity, no user interaction and a changed scope, which is why the score sits so close to the maximum. The temporal score is lower, at 8.9, because Tenable marks exploit code maturity as proof of concept and the remediation level as official fix.
Affected versions are Tenable Identity Exposure SaaS 3.125.0 and earlier. The fixed release is 3.126.0, published on the same day as the advisory. Tenable credits the researcher Takumi Ito for the report.
Upgrading the service is not enough on its own. Tenable says customer action is needed: on each existing installation the listener has to be removed with Register-TenableIOA.ps1 -Uninstall and then installed again after the upgrade. The full release notes carry further instructions, and teams that run the listener on a production PDCe should plan that reinstall rather than assume the cloud-side update has closed the hole.
The timeline in the advisory is short. Tenable received the report on 9 September, confirmed it valid on 24 September, requested the CVE ID and calculated the scores on 2 October, and released the fix on 8 October.
Tenable's security page lists TNS-2026-27 as the newest Identity Exposure advisory.
Company profile on TrustList: Tenable
Sources
Categories & features
- Cybersecurity
- Vulnerability Management
- SaaS
TrustList Weekly
The week in software and IT, in one email
The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.