Tenable · Tenable Identity Exposure · CVE-2026-106126
**Name of the Vulnerable Software and Affected Versions**
Tenable Identity Exposure (SaaS) (affected versions not specified)
**Description**
A command injection flaw exists in the Active Directory Events Listener. This allows an authenticated attacker with low privileges to execute arbitrary commands with SYSTEM privileges on the Primary Domain Controller emulator (PDCe).
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.