T

Threats

Tenable Identity Exposure (SaaS) Critical Command Injection

Overview

  • CVE: CVE-2026-106126

  • Severity: Critical

  • CVSS: 9.4 (v4.0); 9.9 (v3.1 base)

  • Vendor: Tenable, Inc.

  • Product: Tenable Identity Exposure (SaaS)

  • Advisory published: 8 October 2026

  • Latest listed advisory revision: R1, 8 October 2026

Tenable's security advisory TNS-2026-27 identifies a command injection flaw in the Active Directory Events Listener. Organisations using the affected SaaS product should prioritise the complete remediation procedure, including listener redeployment.


Affected Versions

Tenable Identity Exposure (SaaS) - CVE-2026-106126


Vulnerability Breakdown

CVE-2026-106126 - Active Directory Events Listener Command Injection

  • Severity: Critical

  • CVSS: 9.4 (v4.0 base); 9.9 (v3.1 base)

  • Description: A command injection vulnerability in the Active Directory Events Listener allows an authenticated, low-privileged attacker to execute arbitrary commands.

  • Impact: Commands execute as SYSTEM on the PDC emulator (PDCe), compromising the affected domain controller's confidentiality, integrity and availability.

  • Conditions: Authentication with low privileges is required. The vendor's CVSS vectors describe network access, low attack complexity and no user interaction.

  • Notes: Tenable classifies the issue as CWE-78, OS command injection. Upgrading the SaaS version alone does not fully resolve existing listener installations.

  • Source: Tenable technical description and risk information.


Mitigation

  • Upgrade Tenable Identity Exposure (SaaS) to 3.126.0, as required by the vendor security advisory.

  • After upgrading, run Register-TenableIOA.ps1 -Uninstall and reinstall the listener. Both steps are mandatory for existing installations under Tenable's remediation instructions.

  • Follow the Indicators of Attack uninstallation procedure. Use the correct GPO name if it was customised, allow the documented four-hour replication delay, and complete the cleaning-GPO removal procedure.

  • Obtain the current installation script and domain configuration from the upgraded product. Redeploy once per monitored AD domain with the required administrative permissions, following Install Indicators of Attack and the installation-script guidance.

  • Verify listener deployment using the checks in the installation guide. The product's automatic IoA configuration updates do not update the IoA content itself and do not replace redeployment.

Package availability note: During source review on 9 October 2026, the public downloads portal still displayed SaaS 3.125.0, while the security advisory specified 3.126.0 as the fix. Confirm access to the fixed build with Tenable if it is not available. Do not treat 3.125.0 as patched.


Summary for IT Teams

  • Products: Tenable Identity Exposure (SaaS), including the Active Directory Events Listener.

  • Threat Level: Critical, CVSS v4.0 9.4 and CVSS v3.1 9.9.

  • Action Required: Upgrade to 3.126.0, uninstall the existing listener, reinstall from the upgraded product and verify deployment across monitored domains. Follow the complete vendor remediation requirements.


Reference


Need Help?

If your organisation needs assistance assessing or remediating Tenable Identity Exposure, the Secure ISS SOC team is ready to help. Call 1300 769 460 or email the Secure ISS SOC team. We are here to help you strengthen your cybersecurity posture. our details on the Secure ISS contact page.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.