T
Threats
Tenable Identity Exposure (SaaS) Critical Command Injection
Overview
CVE: CVE-2026-106126
Severity: Critical
CVSS: 9.4 (v4.0); 9.9 (v3.1 base)
Vendor: Tenable, Inc.
Product: Tenable Identity Exposure (SaaS)
Advisory published: 8 October 2026
Latest listed advisory revision: R1, 8 October 2026
Tenable's security advisory TNS-2026-27 identifies a command injection flaw in the Active Directory Events Listener. Organisations using the affected SaaS product should prioritise the complete remediation procedure, including listener redeployment.
Affected Versions
Tenable Identity Exposure (SaaS) - CVE-2026-106126
Affected: 3.125.0 and earlier, as specified in Tenable's affected-products statement.
Fixed: 3.126.0. Existing installations must also uninstall and reinstall the listener after upgrading to fully resolve the issue, according to Tenable's solution requirements.
Not affected: The advisory does not explicitly identify unaffected versions, platforms or configurations. It names the SaaS product; it does not establish the status of on-premises releases.
Source: Tenable TNS-2026-27 security advisory and Tenable Identity Exposure 2026 SaaS release notes, version 3.126.
Vulnerability Breakdown
CVE-2026-106126 - Active Directory Events Listener Command Injection
Severity: Critical
CVSS: 9.4 (v4.0 base); 9.9 (v3.1 base)
Description: A command injection vulnerability in the Active Directory Events Listener allows an authenticated, low-privileged attacker to execute arbitrary commands.
Impact: Commands execute as SYSTEM on the PDC emulator (PDCe), compromising the affected domain controller's confidentiality, integrity and availability.
Conditions: Authentication with low privileges is required. The vendor's CVSS vectors describe network access, low attack complexity and no user interaction.
Notes: Tenable classifies the issue as CWE-78, OS command injection. Upgrading the SaaS version alone does not fully resolve existing listener installations.
Mitigation
Upgrade Tenable Identity Exposure (SaaS) to 3.126.0, as required by the vendor security advisory.
After upgrading, run Register-TenableIOA.ps1 -Uninstall and reinstall the listener. Both steps are mandatory for existing installations under Tenable's remediation instructions.
Follow the Indicators of Attack uninstallation procedure. Use the correct GPO name if it was customised, allow the documented four-hour replication delay, and complete the cleaning-GPO removal procedure.
Obtain the current installation script and domain configuration from the upgraded product. Redeploy once per monitored AD domain with the required administrative permissions, following Install Indicators of Attack and the installation-script guidance.
Verify listener deployment using the checks in the installation guide. The product's automatic IoA configuration updates do not update the IoA content itself and do not replace redeployment.
Package availability note: During source review on 9 October 2026, the public downloads portal still displayed SaaS 3.125.0, while the security advisory specified 3.126.0 as the fix. Confirm access to the fixed build with Tenable if it is not available. Do not treat 3.125.0 as patched.
Summary for IT Teams
Products: Tenable Identity Exposure (SaaS), including the Active Directory Events Listener.
Threat Level: Critical, CVSS v4.0 9.4 and CVSS v3.1 9.9.
Action Required: Upgrade to 3.126.0, uninstall the existing listener, reinstall from the upgraded product and verify deployment across monitored domains. Follow the complete vendor remediation requirements.
Reference
Tenable TNS-2026-27: Identity Exposure SaaS 3.126.0 security advisory
Tenable Identity Exposure 2026 SaaS release notes, version 3.126
Need Help?
If your organisation needs assistance assessing or remediating Tenable Identity Exposure, the Secure ISS SOC team is ready to help. Call 1300 769 460 or email the Secure ISS SOC team. We are here to help you strengthen your cybersecurity posture. our details on the Secure ISS contact page.

