Back to overview

CVE-2026-13007

HIGH
7.5
CVSS 3.1
Description
Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive application configuration data including cleartext LDAP credentials, SAML configuration, user accounts, and directory settings to unauthenticated remote attackers. Affected responses are served with Cache-Control: public headers and without Vary: Cookie, allowing reverse proxies and CDNs to cache and serve sensitive data to unauthenticated users even after authentication is applied.

Metadata

CVE ID
CVE-2026-13007
State
PUBLISHED
Assigner
tenable
Reserved
2026-06-23 14:57 UTC
Published
2026-06-23 15:59 UTC
Last updated
2026-06-23 17:48 UTC
Primary CWE
CWE-306
Missing Authentication for Critical Function
Vendor / Product
tenable / Tenable Identity Exposure
Sources
cve.org  ·  NVD

Severity & Metrics

7.5 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
tenable Tenable Identity Exposure 0 < 3.93.5
Weakness (CWE)
CWESourceDescription
CWE-306 cna Missing Authentication for Critical Function
CWE-524 cna Use of Cache Containing Sensitive Information
CVSS scores (2)
ScoreSeverityVersionSourceVector
8.5 HIGH 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:N
7.5 HIGH 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Back to overview