Tenable · Tenable Identity Exposure · CVE-2026-13007
**Name of the Vulnerable Software and Affected Versions**
Tenable Identity Exposure (affected versions not specified)
**Description**
Multiple unauthenticated API endpoints under '/w/api/*' expose sensitive application configuration data to remote attackers. The leaked information includes cleartext LDAP credentials, SAML configuration, user accounts, and directory settings. Additionally, affected responses are served with Cache-Control: public headers and without Vary: Cookie, which allows reverse proxies and Content Delivery Networks (CDNs) to cache and serve this sensitive data to unauthenticated users even after authentication is implemented.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.