VDB

ESB-2026.6951

ESB-2026.6951 PUBLISHED CVSS 9.899999618530273 CRITICAL

=========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2026.6951 [R1] Tenable Identity Exposure Version 3.93.5 Fixes Multiple Vulnerabilities 24 June 2026 =========================================================================== AUSCERT Security Bulletin Summary --------------------------------- Product: Tenable Identity Exposure Publisher: Tenable Operating System: Windows UNIX variants (UNIX, Linux, OSX) Resolution: Patch/Upgrade CVE Names: CVE-2025-14524 CVE-2025-14819 CVE-2025-15079 CVE-2025-15224 CVE-2026-32167 CVE-2026-32176 CVE-2026-33120 CVE-2026-26130 CVE-2026-26171 CVE-2026-32178 CVE-2026-32203 CVE-2026-33116 CVE-2025-14017 CVE-2025-55247 CVE-2025-55248 CVE-2025-55315 CVE-2025-55130 CVE-2025-55131 CVE-2025-55132 CVE-2025-59465 CVE-2025-59466 CVE-2026-21637 CVE-2026-1965 CVE-2026-3783 CVE-2026-3784 CVE-2026-3805 CVE-2025-11187 CVE-2025-15467 CVE-2025-15468 CVE-2025-15469 CVE-2025-66199 CVE-2025-68160 CVE-2025-69418 CVE-2025-69419 CVE-2025-69420 CVE-2025-69421 CVE-2026-22795 CVE-2026-22796 CVE-2025-13034 CVE-2026-6253 CVE-2026-6429 CVE-2026-6276 CVE-2026-5773 CVE-2026-5545 CVE-2026-4873 CVE-2026-32175 CVE-2026-32177 CVE-2026-35433 CVE-2026-7168 CVE-2026-42899 CVE-2026-2673 CVE-2026-28387 CVE-2026-28388 CVE-2026-28389 CVE-2026-28390 CVE-2026-31789 CVE-2026-31790 CVE-2026-13007 CVE-2026-7009 CVE-2026-28386 CVE-2026-35188 CVE-2026-42765 CVE-2026-42771 CVE-2026-42789 CVE-2026-42790 CVE-2026-34180 CVE-2026-34182 CVE-2026-42766 CVE-2026-42767 CVE-2026-45447 CVE-2026-7383 CVE-2026-9076 CVE-2026-40370 CVE-2026-34181 CVE-2026-34183 CVE-2026-42764 CVE-2026-42768 CVE-2026-42769 CVE-2026-42770 CVE-2026-45445 CVE-2026-45446 CVE-2026-21218 CVE-2026-21710 CVE-2026-21713 CVE-2026-21714 CVE-2026-21715 CVE-2026-21716 CVE-2026-21717 CVE-2026-45490 CVE-2026-45491 CVE-2026-45591 CVE-2026-21262 Original Bulletin: https://www.tenable.com/security/tns-2026-16 Comment: CVSS (Max): 9.9 CVE-2025-55315 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L) CVSS Source: NIST, HackerOne, [Microsoft Corporation], CISA-ADP, Tenable Network Security Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L EPSS (Max): 66.3% (99th)* CVE-2025-55315 2026-06-23 * Not all EPSS found when published - --------------------------BEGIN INCLUDED TEXT-------------------- [R1] Tenable Identity Exposure Version 3.93.5 Fixes Multiple Vulnerabilities Critical Synopsis Tenable Identity Exposure leverages third-party software to help provide underlying functionality. Several of the third-party components (.NET Windows Server Hosting, NodeJS, Erlang OTP, SQL Server, OpenSSL, Curl) were found to contain vulnerabilities, and updated versions have been made available by the providers. Out of caution and in line with best practice, Tenable has opted to upgrade these components to address the potential impact of the issues. Tenable Identity Exposure version 3.93.5 updates .NET Windows Server Hosting to version 8.0.28.26269, NodeJS to version 20.20.2.0, Erlang OTP to version 26.2.5.21, SQL Server to version 15.0.4470.1, OpenSSL to version 4.0.1, and Curl to version 8.19.0 to address the identified vulnerabilities. Tenable Identity Exposure version v3.93.5 also resolves a vulnerability related to API endpoints returning information to unauthenticated GET requests (CVE-2026-13007). Base Temporal CVSSv3 CVSSv4 CVSSv4 CVE ID Score Score Vector Base Vector CWE Score CVSS:3.1/ AV:L/AC:L/ MEDIUM PR:L/UI:R/ CWE-121: CVE-2025-11187 6.1 5.3 S:U/C:L/ - - Stack-based Buffer I:L/A:H/ Overflow E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:H/ CWE-345: MEDIUM PR:N/UI:N/ Insufficient CVE-2025-13034 5.9 5.1 S:U/C:N/ - - Verification of I:H/A:N/ Data Authenticity E:U/RL:O/ RC:C CVSS:3.1/ AV:L/AC:H/ MEDIUM PR:N/UI:R/ CWE-416: Use After CVE-2025-14017 6.3 5.5 S:U/C:H/ - - Free I:H/A:N/ E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:H/ CWE-200: Exposure MEDIUM PR:N/UI:R/ of Sensitive CVE-2025-14524 5.3 4.6 S:U/C:H/ - - Information to an I:N/A:N/ Unauthorized Actor E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:H/ CWE-200: Exposure MEDIUM PR:N/UI:R/ of Sensitive CVE-2025-14819 5.3 4.6 S:U/C:H/ - - Information to an I:N/A:N/ Unauthorized Actor E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:H/ CWE-200: Exposure MEDIUM PR:N/UI:R/ of Sensitive CVE-2025-15079 5.3 4.6 S:U/C:H/ - - Information to an I:N/A:N/ Unauthorized Actor E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:H/ LOW PR:N/UI:R/ CWE-284: Improper CVE-2025-15224 3.1 2.7 S:U/C:N/ - - Access Control I:L/A:N/ E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ HIGH PR:N/UI:R/ CWE-416: Use After CVE-2025-15467 8.8 7.6 S:U/C:H/ - - Free I:H/A:H/ E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:H/ CWE-400: MEDIUM PR:N/UI:N/ Uncontrolled CVE-2025-15468 5.9 5.1 S:U/C:N/ - - Resource I:N/A:H/ Consumption E:U/RL:O/ RC:C CVSS:3.1/ AV:L/AC:L/ MEDIUM PR:L/UI:N/ CWE-284: Improper CVE-2025-15469 5.5 4.8 S:U/C:N/ - - Access Control I:H/A:N/ E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ CRITICAL PR:N/UI:N/ CWE-287: Improper CVE-2025-55130 9.1 7.9 S:U/C:H/ - - Authentication I:H/A:N/ E:U/RL:O/ RC:C CVSS:3.0/ CWE-362: Concurrent AV:N/AC:H/ Execution using HIGH PR:L/UI:N/ Shared Resource CVE-2025-55131 7.1 6.2 S:U/C:H/ - - with Improper I:H/A:L/ Synchronization E:U/RL:O/ ('Race Condition') RC:C CVSS:3.1/ CVSS:4.0/ AV:N/AC:L/ AV:L/AC:L/ CWE-200: Exposure MEDIUM PR:N/UI:N/ AT:N/PR:L/ of Sensitive CVE-2025-55132 5.3 4.6 S:U/C:L/ 4.8 UI:N/VC:N/ Information to an I:N/A:N/ VI:L/VA:N/ Unauthorized Actor E:U/RL:O/ SC:N/SI:N/ RC:C SA:N CVSS:3.1/ AV:L/AC:L/ HIGH PR:L/UI:R/ CWE-269: Improper CVE-2025-55247 7.3 6.3 S:U/C:H/ - - Privilege I:H/A:H/ Management E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ CWE-200: Exposure MEDIUM PR:L/UI:R/ of Sensitive CVE-2025-55248 5.7 5 S:U/C:H/ - - Information to an I:N/A:N/ Unauthorized Actor E:U/RL:O/ RC:C CVSS:3.1/ CWE-444: AV:N/AC:L/ Inconsistent CRITICAL PR:L/UI:N/ Interpretation of CVE-2025-55315 9.9 8.6 S:C/C:H/ - - HTTP Requests I:H/A:L/ ('HTTP Request/ E:U/RL:O/ Response RC:C Smuggling') CVSS:3.0/ AV:N/AC:L/ CWE-400: HIGH PR:N/UI:N/ Uncontrolled CVE-2025-59465 7.5 6.5 S:U/C:N/ - - Resource I:N/A:H/ Consumption E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ CWE-400: HIGH PR:N/UI:N/ Uncontrolled CVE-2025-59466 7.5 6.5 S:U/C:N/ - - Resource I:N/A:H/ Consumption E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:H/ CWE-400: MEDIUM PR:N/UI:N/ Uncontrolled CVE-2025-66199 5.9 5.1 S:U/C:N/ - - Resource I:N/A:H/ Consumption E:U/RL:O/ RC:C CVSS:3.1/ AV:L/AC:H/ CWE-400: MEDIUM PR:L/UI:N/ Uncontrolled CVE-2025-68160 4.7 4.1 S:U/C:N/ - - Resource I:N/A:H/ Consumption E:U/RL:O/ RC:C CVSS:3.1/ AV:L/AC:H/ CWE-200: Exposure MEDIUM PR:N/UI:N/ of Sensitive CVE-2025-69418 4 3.5 S:U/C:L/ - - Information to an I:L/A:N/ Unauthorized Actor E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:H/ HIGH PR:N/UI:N/ CWE-295: Improper CVE-2025-69419 7.4 6.4 S:U/C:H/ - - Certificate I:H/A:N/ Validation E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ CWE-400: HIGH PR:N/UI:N/ Uncontrolled CVE-2025-69420 7.5 6.5 S:U/C:N/ - - Resource I:N/A:H/ Consumption E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ CWE-400: HIGH PR:N/UI:N/ Uncontrolled CVE-2025-69421 7.5 6.5 S:U/C:N/ - - Resource I:N/A:H/ Consumption E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ MEDIUM PR:L/UI:N/ CWE-284: Improper CVE-2026-1965 6.5 5.7 S:U/C:N/ - - Access Control I:H/A:N/ E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ MEDIUM PR:N/UI:N/ CWE-284: Improper CVE-2026-2673 6.5 5.7 S:U/C:N/ - - Access Control I:L/A:L/ E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ CWE-200: Exposure MEDIUM PR:N/UI:N/ of Sensitive CVE-2026-3783 5.3 4.6 S:U/C:L/ - - Information to an I:N/A:N/ Unauthorized Actor E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ CWE-200: Exposure MEDIUM PR:N/UI:N/ of Sensitive CVE-2026-3784 6.5 5.7 S:U/C:L/ - - Information to an I:L/A:N/ Unauthorized Actor E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ CWE-400: HIGH PR:N/UI:N/ Uncontrolled CVE-2026-3805 7.5 6.5 S:U/C:N/ - - Resource I:N/A:H/ Consumption E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:H/ CWE-200: Exposure MEDIUM PR:N/UI:N/ of Sensitive CVE-2026-4873 5.9 5.1 S:U/C:H/ - - Information to an I:N/A:N/ Unauthorized Actor E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:H/ MEDIUM PR:N/UI:N/ CWE-284: Improper CVE-2026-5545 6.5 5.7 S:U/C:L/ - - Access Control I:H/A:N/ E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ CWE-200: Exposure HIGH PR:N/UI:N/ of Sensitive CVE-2026-5773 7.5 6.5 S:U/C:H/ - - Information to an I:N/A:N/ Unauthorized Actor E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:H/ CWE-400: MEDIUM PR:N/UI:N/ Uncontrolled CVE-2026-6253 5.9 5.1 S:U/C:N/ - - Resource I:N/A:H/ Consumption E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ CWE-400: HIGH PR:N/UI:N/ Uncontrolled CVE-2026-6276 7.5 6.5 S:U/C:N/ - - Resource I:N/A:H/ Consumption E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:H/ CWE-200: Exposure MEDIUM PR:L/UI:N/ of Sensitive CVE-2026-6429 5.3 4.6 S:U/C:H/ - - Information to an I:N/A:N/ Unauthorized Actor E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ CWE-200: Exposure MEDIUM PR:N/UI:N/ of Sensitive CVE-2026-7009 5.3 4.6 S:U/C:L/ - - Information to an I:N/A:N/ Unauthorized Actor E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ CWE-200: Exposure MEDIUM PR:N/UI:N/ of Sensitive CVE-2026-7168 5.3 4.6 S:U/C:L/ - - Information to an I:N/A:N/ Unauthorized Actor E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:H/ HIGH PR:N/UI:N/ CWE-295: Improper CVE-2026-7383 8.1 7 S:U/C:H/ - - Certificate I:H/A:H/ Validation E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ CWE-400: HIGH PR:N/UI:N/ Uncontrolled CVE-2026-9076 7.5 6.5 S:U/C:N/ - - Resource I:N/A:H/ Consumption E:U/RL:O/ RC:C CVSS:3.1/ CVSS:4.0/ CWE-306: Missing AV:N/AC:L/ AV:N/AC:L/ Authentication for HIGH PR:N/UI:N/ AT:N/PR:N/ Critical Function; CVE-2026-13007 7.5 6.5 S:U/C:H/ 8.7 UI:N/VC:H/ CWE-524: Use of I:N/A:N/ VI:N/VA:N/ Cache Containing E:U/RL:O/ SC:L/SI:L/ Sensitive RC:C SA:N Information CVSS:3.0/ CVSS:4.0/ AV:N/AC:L/ AV:N/AC:L/ HIGH PR:N/UI:N/ AT:N/PR:N/ CWE-284: Improper CVE-2026-21218 7.5 6.5 S:U/C:N/ 8.7 UI:N/VC:N/ Access Control I:H/A:N/ VI:H/VA:N/ E:U/RL:O/ SC:N/SI:N/ RC:C SA:N CVSS:3.1/ AV:N/AC:L/ HIGH PR:L/UI:N/ CWE-284: Improper CVE-2026-21262 8.8 7.6 S:U/C:H/ - - Access Control I:H/A:H/ E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ CWE-400: HIGH PR:N/UI:N/ Uncontrolled CVE-2026-21637 7.5 6.5 S:U/C:N/ - - Resource I:N/A:H/ Consumption E:U/RL:O/ RC:C CVSS:3.0/ AV:N/AC:L/ CWE-400: HIGH PR:N/UI:N/ Uncontrolled CVE-2026-21710 7.5 6.5 S:U/C:N/ - - Resource I:N/A:H/ Consumption E:U/RL:O/ RC:C CVSS:3.0/ AV:N/AC:H/ CWE-200: Exposure MEDIUM PR:N/UI:N/ of Sensitive CVE-2026-21713 5.9 5.1 S:U/C:H/ - - Information to an I:N/A:N/ Unauthorized Actor E:U/RL:O/ RC:C CVSS:3.0/ AV:N/AC:L/ CWE-400: MEDIUM PR:N/UI:N/ Uncontrolled CVE-2026-21714 5.3 4.6 S:U/C:N/ - - Resource I:N/A:L/ Consumption E:U/RL:O/ RC:C CVSS:3.0/ AV:L/AC:L/ CWE-200: Exposure LOW PR:L/UI:N/ of Sensitive CVE-2026-21715 3.3 2.9 S:U/C:L/ - - Information to an I:N/A:N/ Unauthorized Actor E:U/RL:O/ RC:C CVSS:3.0/ AV:L/AC:L/ LOW PR:L/UI:N/ CWE-284: Improper CVE-2026-21716 3.3 2.9 S:U/C:N/ - - Access Control I:L/A:N/ E:U/RL:O/ RC:C CVSS:3.0/ AV:N/AC:H/ CWE-400: MEDIUM PR:N/UI:N/ Uncontrolled CVE-2026-21717 5.9 5.1 S:U/C:N/ - - Resource I:N/A:H/ Consumption E:U/RL:O/ RC:C CVSS:3.1/ AV:L/AC:L/ CWE-400: MEDIUM PR:N/UI:R/ Uncontrolled CVE-2026-22795 5.5 4.8 S:U/C:N/ - - Resource I:N/A:H/ Consumption E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ CWE-400: MEDIUM PR:N/UI:N/ Uncontrolled CVE-2026-22796 5.3 4.6 S:U/C:N/ - - Resource I:N/A:L/ Consumption E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ CWE-400: HIGH PR:N/UI:N/ Uncontrolled CVE-2026-26130 7.5 6.5 S:U/C:N/ - - Resource I:N/A:H/ Consumption E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ CWE-400: HIGH PR:N/UI:N/ Uncontrolled CVE-2026-26171 7.5 6.5 S:U/C:N/ - - Resource I:N/A:H/ Consumption E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ HIGH PR:N/UI:N/ CWE-125: CVE-2026-28386 7.5 6.5 S:U/C:N/ - - Out-of-bounds Read I:N/A:H/ E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:H/ HIGH PR:N/UI:N/ CWE-295: Improper CVE-2026-28387 8.1 7 S:U/C:H/ - - Certificate I:H/A:H/ Validation E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ CWE-400: HIGH PR:N/UI:N/ Uncontrolled CVE-2026-28388 7.5 6.5 S:U/C:N/ - - Resource I:N/A:H/ Consumption E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ CWE-400: HIGH PR:N/UI:N/ Uncontrolled CVE-2026-28389 7.5 6.5 S:U/C:N/ - - Resource I:N/A:H/ Consumption E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ CWE-400: HIGH PR:N/UI:N/ Uncontrolled CVE-2026-28390 7.5 6.5 S:U/C:N/ - - Resource I:N/A:H/ Consumption E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ CWE-119: Improper CRITICAL PR:N/UI:N/ Restriction of CVE-2026-31789 9.8 8.5 S:U/C:H/ - - Operations within I:H/A:H/ the Bounds of a E:U/RL:O/ Memory Buffer RC:C CVSS:3.1/ AV:N/AC:L/ CWE-200: Exposure HIGH PR:N/UI:N/ of Sensitive CVE-2026-31790 7.5 6.5 S:U/C:H/ - - Information to an I:N/A:N/ Unauthorized Actor E:U/RL:O/ RC:C CVSS:3.1/ CWE-89: Improper AV:L/AC:L/ Neutralization of HIGH PR:L/UI:N/ Special Elements CVE-2026-32167 7.8 6.8 S:U/C:H/ - - used in an SQL I:H/A:H/ Command ('SQL E:U/RL:O/ Injection') RC:C CVSS:3.1/ AV:N/AC:L/ MEDIUM PR:L/UI:N/ CWE-284: Improper CVE-2026-32175 4.3 3.8 S:U/C:N/ - - Access Control I:L/A:N/ E:U/RL:O/ RC:C CVSS:3.1/ CWE-89: Improper AV:L/AC:L/ Neutralization of HIGH PR:L/UI:N/ Special Elements CVE-2026-32176 7.8 6.8 S:U/C:H/ - - used in an SQL I:H/A:H/ Command ('SQL E:U/RL:O/ Injection') RC:C CVSS:3.1/ AV:L/AC:L/ HIGH PR:N/UI:R/ CWE-269: Improper CVE-2026-32177 7.3 6.3 S:U/C:H/ - - Privilege I:H/A:L/ Management E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ CWE-200: Exposure HIGH PR:N/UI:N/ of Sensitive CVE-2026-32178 7.5 6.5 S:U/C:H/ - - Information to an I:N/A:N/ Unauthorized Actor E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ CWE-400: HIGH PR:N/UI:N/ Uncontrolled CVE-2026-32203 7.5 6.5 S:U/C:N/ - - Resource I:N/A:H/ Consumption E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ CWE-400: HIGH PR:N/UI:N/ Uncontrolled CVE-2026-33116 7.5 6.5 S:U/C:N/ - - Resource I:N/A:H/ Consumption E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ HIGH PR:L/UI:N/ CWE-822: Untrusted CVE-2026-33120 8.8 7.6 S:U/C:H/ - - Pointer Dereference I:H/A:H/ E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ CWE-400: HIGH PR:N/UI:N/ Uncontrolled CVE-2026-34180 7.5 6.5 S:U/C:N/ - - Resource I:N/A:H/ Consumption E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:H/ HIGH PR:N/UI:N/ CWE-295: Improper CVE-2026-34181 7.4 6.4 S:U/C:H/ - - Certificate I:H/A:N/ Validation E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ CRITICAL PR:N/UI:N/ CWE-287: Improper CVE-2026-34182 9.1 7.9 S:U/C:H/ - - Authentication I:H/A:N/ E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ CWE-400: HIGH PR:N/UI:N/ Uncontrolled CVE-2026-34183 7.5 6.5 S:U/C:N/ - - Resource I:N/A:H/ Consumption E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:H/ CWE-200: Exposure MEDIUM PR:L/UI:N/ of Sensitive CVE-2026-35188 5 4.4 S:U/C:L/ - - Information to an I:L/A:L/ Unauthorized Actor E:U/RL:O/ RC:C CVSS:3.1/ AV:L/AC:L/ HIGH PR:N/UI:R/ CWE-269: Improper CVE-2026-35433 7.3 6.3 S:U/C:H/ - - Privilege I:H/A:L/ Management E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ HIGH PR:L/UI:N/ CWE-73: External CVE-2026-40370 8.8 7.6 S:U/C:H/ - - Control of File I:H/A:H/ Name or Path E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ CWE-400: HIGH PR:N/UI:N/ Uncontrolled CVE-2026-42764 7.5 6.5 S:U/C:N/ - - Resource I:N/A:H/ Consumption E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ CWE-400: HIGH PR:N/UI:N/ Uncontrolled CVE-2026-42765 7.5 6.5 S:U/C:N/ - - Resource I:N/A:H/ Consumption E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:H/ CWE-400: MEDIUM PR:N/UI:N/ Uncontrolled CVE-2026-42766 5.9 5.1 S:U/C:N/ - - Resource I:N/A:H/ Consumption E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:H/ CWE-400: MEDIUM PR:N/UI:N/ Uncontrolled CVE-2026-42767 5.9 5.1 S:U/C:N/ - - Resource I:N/A:H/ Consumption E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:H/ CWE-200: Exposure LOW PR:N/UI:N/ of Sensitive CVE-2026-42768 3.7 3.2 S:U/C:L/ - - Information to an I:N/A:N/ Unauthorized Actor E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:H/ CWE-200: Exposure MEDIUM PR:L/UI:N/ of Sensitive CVE-2026-42769 5.3 4.6 S:U/C:H/ - - Information to an I:N/A:N/ Unauthorized Actor E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:H/ CWE-200: Exposure LOW PR:N/UI:N/ of Sensitive CVE-2026-42770 3.7 3.2 S:U/C:L/ - - Information to an I:N/A:N/ Unauthorized Actor E:U/RL:O/ RC:C CVSS:3.1/ AV:L/AC:L/ CWE-400: MEDIUM PR:N/UI:N/ Uncontrolled CVE-2026-42771 6.2 5.4 S:U/C:N/ - - Resource I:N/A:H/ Consumption E:U/RL:O/ RC:C CVSS:3.1/ CVSS:4.0/ AV:N/AC:H/ AV:N/AC:L/ MEDIUM PR:N/UI:N/ AT:P/PR:N/ CWE-295: Improper CVE-2026-42789 4.8 4.2 S:U/C:L/ 7 UI:N/VC:L/ Certificate I:L/A:N/ VI:L/VA:N/ Validation E:U/RL:O/ SC:H/SI:H/ RC:C SA:N CVSS:3.1/ CVSS:4.0/ AV:N/AC:L/ AV:N/AC:H/ HIGH PR:N/UI:R/ AT:P/PR:N/ CWE-295: Improper CVE-2026-42790 8.1 7 S:U/C:H/ 7.6 UI:P/VC:H/ Certificate I:H/A:N/ VI:H/VA:N/ Validation E:U/RL:O/ SC:N/SI:N/ RC:C SA:N CVSS:3.1/ AV:N/AC:L/ CWE-400: HIGH PR:N/UI:N/ Uncontrolled CVE-2026-42899 7.5 6.5 S:U/C:N/ - - Resource I:N/A:H/ Consumption E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ CWE-200: Exposure HIGH PR:N/UI:N/ of Sensitive CVE-2026-45445 7.5 6.5 S:U/C:H/ - - Information to an I:N/A:N/ Unauthorized Actor E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:H/ MEDIUM PR:N/UI:N/ CWE-295: Improper CVE-2026-45446 4.8 4.2 S:U/C:L/ - - Certificate I:L/A:N/ Validation E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ HIGH PR:L/UI:N/ CWE-287: Improper CVE-2026-45447 8.8 7.6 S:U/C:H/ - - Authentication I:H/A:H/ E:U/RL:O/ RC:C CVSS:3.1/ AV:L/AC:L/ HIGH PR:L/UI:N/ CWE-269: Improper CVE-2026-45490 7.8 6.8 S:U/C:H/ - - Privilege I:H/A:H/ Management E:U/RL:O/ RC:C CVSS:3.1/ AV:L/AC:L/ MEDIUM PR:L/UI:N/ CWE-284: Improper CVE-2026-45491 5.5 4.8 S:U/C:N/ - - Access Control I:H/A:N/ E:U/RL:O/ RC:C CVSS:3.1/ AV:N/AC:L/ CWE-400: HIGH PR:N/UI:N/ Uncontrolled CVE-2026-45591 7.5 6.5 S:U/C:N/ - - Resource I:N/A:H/ Consumption E:U/RL:O/ RC:C Solution Tenable has released Tenable Identity Exposure version 3.93.5 to address these issues. The installation files can be obtained from the Tenable Downloads Portal: https://www.tenable.com/downloads/identity-exposure Additional References https://docs.tenable.com/release-notes/Content/identity-exposure/onprem/ 2026.htm#Tenable-Identity-Exposure-3.93.5-(2026-06-23)- This page contains information regarding security vulnerabilities that may impact Tenable's products. This may include issues specific to our software, or due to the use of third-party libraries within our software. Tenable strongly encourages users to ensure that they upgrade or apply relevant patches in a timely manner. Tenable takes product security very seriously. If you believe you have found a vulnerability in one of our products, we ask that you please work with us to quickly resolve it in order to protect customers. Tenable believes in responding quickly to such reports, maintaining communication with researchers, and providing a solution in short order. For more details on submitting vulnerability information, please see our Vulnerability Reporting Guidelines page. If you have questions or corrections about this advisory, please email [email protected] Risk Information Tenable Advisory ID: TNS-2026-16 Risk Factor: Critical Affected Products Tenable Identity Exposure 3.93.4 and earlier Disclosure Timeline 2026-06-07 - Report received by Tenable 2026-06-11 - Report accepted by Tenable 2026-06-23 - CVE ID requested / CVSS Scoring calculated 2026-06-23 - Advisory Timeline 2026-06-23 - [R1] Initial Release > - --------------------------END INCLUDED TEXT---------------------- You have received this e-mail bulletin as a result of your organisation's registration with AUSCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AUSCERT's members. As AUSCERT did not write the document quoted above, AUSCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AUSCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: https://portal.auscert.org.au/bulletins/ =========================================================================== AUSCERT The University of Queensland, Brisbane QLD 4072 Australia e: auscert@auscert.org.au t: +61 (0)7 3365 4417 Allies in Cyber Security ===========================================================================

Risk Scores

CVSS 3.1
9.899999618530273
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L

Affected Products

VendorProductVersions
TenableTenable Identity Exposure

Timeline

  • Jun 24, 2026 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›