CVE-2026-106126
CRITICAL
NVD
CVSS Score
9.9
Severity
CRITICAL
Published
Oct 08, 2026
Vendor
unknown
Description
A command injection vulnerability in the Active Directory Events Listener of Tenable Identity Exposure (SaaS) allows an authenticated, low-privileged attacker to execute arbitrary commands as SYSTEM on the PDCe.