CVE-2026-106126: Tenable Identity Exposure SYSTEM injection, CVSS 9.9
command injection on the primary domain controller emulator

CVE-2026-106126: Tenable Identity Exposure SYSTEM injection, CVSS 9.9

Tenable patched CVE-2026-106126 in Tenable Identity Exposure SaaS. A command injection in the Active Directory Events Listener lets an authenticated, low-privileged user run operating-system commands as SYSTEM on the primary domain controller emulator.

What happened

The listener is installed on domain controllers so it can collect security events and forward them to the Tenable SaaS service. The deployment script, Register-TenableIOA.ps1, sets up a WMI Active Script Consumer. That is the path a low-privilege account can abuse.

Tenable rates the bug CVSS 9.9 on version 3 and 9.4 on version 4. Advisory TNS-2026-27, addressed in SaaS version 3.126.0, does not describe active exploitation. The placement still makes it urgent. The vulnerable component sits on the domain controller that holds the PDC emulator role.

Who is affected

Tenable Identity Exposure SaaS installations that still run the Active Directory Events Listener from a build before 3.126.0. Confirm the deployment type against the advisory before you scope the change. The listener is on the domain controller, not only in the cloud tenant.

  • An attacker needs a low-privilege authenticated foothold. This is not a pre-authentication internet bug.
  • Success is SYSTEM on the PDCe. In practice that is a short step from control of the domain.
  • The fix is incomplete if the old WMI consumer is left in place after the version upgrade.

What to do now

Upgrade to Tenable Identity Exposure SaaS 3.126.0, then uninstall and reinstall the listener. The upgrade alone does not clear the vulnerable consumer.

  • After the upgrade, run Register-TenableIOA.ps1 with the Uninstall flag, then install the listener again. Tenable marks that step as required.
  • While the change is pending, watch the PDCe for unexpected processes spawned from the Tenable listener script.
  • Treat unexplained SYSTEM activity on the PDCe since the listener was installed as a possible incident, not as noise.

Source: Tenable, TNS-2026-27.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

CVE-2026-21589: Atlassian Data Center file read at CVSS 9.3
unauthenticated file read in Jira, Confluence, Bitbucket, and Crowd