Back to database
Act now94Critical9.4VulnerabilityCVE-2026-106126No patch link observed

CVE-2026-106126 — A command injection vulnerability in the Active Directory Events Listener of Tenable Identity Exposure (SaaS) allows an authenticated, low-privileg…

Published Oct 8, 2026, 08:17 PM UTCIngested 1h agoSource NVD(cve-db)CVE-2026-106126

Description

A command injection vulnerability in the Active Directory Events Listener of Tenable Identity Exposure (SaaS) allows an authenticated, low-privileged attacker to execute arbitrary commands as SYSTEM on the PDCe.

CVSS v4.0 base metrics

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
9.4

Critical severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Network

Attack Vector

AC

Low

Attack Complexity

AT

None

Attack Requirements

PR

Low

Privileges Required

UI

None

User Interaction

VC

High

Confidentiality (Vulnerable System)

VI

High

Integrity (Vulnerable System)

VA

High

Availability (Vulnerable System)

SC

High

Confidentiality (Subsequent System)

SI

High

Integrity (Subsequent System)

SA

High

Availability (Subsequent System)