Tenable patched CVE-2026-106126 in Tenable Identity Exposure SaaS. A command injection in the Active Directory Events Listener lets an authenticated, low-privileged user run operating-system commands as SYSTEM on the primary domain controller emulator.
What happened
The listener is installed on domain controllers so it can collect security events and forward them to the Tenable SaaS service. The deployment script, Register-TenableIOA.ps1, sets up a WMI Active Script Consumer. That is the path a low-privilege account can abuse.
Tenable rates the bug CVSS 9.9 on version 3 and 9.4 on version 4. Advisory TNS-2026-27, addressed in SaaS version 3.126.0, does not describe active exploitation. The placement still makes it urgent. The vulnerable component sits on the domain controller that holds the PDC emulator role.
Who is affected
Tenable Identity Exposure SaaS installations that still run the Active Directory Events Listener from a build before 3.126.0. Confirm the deployment type against the advisory before you scope the change. The listener is on the domain controller, not only in the cloud tenant.
- An attacker needs a low-privilege authenticated foothold. This is not a pre-authentication internet bug.
- Success is SYSTEM on the PDCe. In practice that is a short step from control of the domain.
- The fix is incomplete if the old WMI consumer is left in place after the version upgrade.
What to do now
Upgrade to Tenable Identity Exposure SaaS 3.126.0, then uninstall and reinstall the listener. The upgrade alone does not clear the vulnerable consumer.
- After the upgrade, run Register-TenableIOA.ps1 with the Uninstall flag, then install the listener again. Tenable marks that step as required.
- While the change is pending, watch the PDCe for unexpected processes spawned from the Tenable listener script.
- Treat unexplained SYSTEM activity on the PDCe since the listener was installed as a possible incident, not as noise.
Source: Tenable, TNS-2026-27.
Also on the blog
- CVE-2026-107406: NetScaler SAML RCE at CVSS 9.5
- AhsayCBS CVE-2026-105134: SYSTEM RCE, 5 organizations hit
- CVE-2026-21589: Atlassian Data Center file read at CVSS 9.3
- FBI seizes 7 Flax Typhoon domains used for Microscan and FishHub
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.