CVE-2026-106126: Command Injection
Published Oct 8, 2026
·Updated
A command injection vulnerability in the Active Directory Events Listener of Tenable Identity Exposure (SaaS) allows an authenticated, low-privileged attacker to execute arbitrary commands as SYSTEM on the PDCe.
Affected Software
1 affected component
Tenable Identity Exposure (SaaS)
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Operational
After upgrading, run `Register-TenableIOA.ps1 -Uninstall` and reinstall the Active Directory Events Listener.
Event History
Oct 8, 2026
CVE Published
via MITRE·07:47 PM
Data Sourced
via MITRE·07:47 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
An attacker must be authenticated and have low-privileged access. No user interaction is required.
2
What is the potential impact on the affected environment?
Successful exploitation allows arbitrary command execution as SYSTEM on the Primary Domain Controller emulator (PDCe), with high impact to confidentiality, integrity, and availability.