Executive brief
Tenable Identity Exposure, a tool used to secure corporate directory services, contains a flaw where sensitive configuration data is accessible without a password. An attacker could remotely retrieve critical information such as cleartext LDAP credentials, user account details, and security settings. This exposure could lead to unauthorized access to the organization's internal directory and broader network infrastructure.
Technical details
Tenable Identity Exposure versions prior to 3.93.5 suffer from missing authentication on several API endpoints located under the /w/api/* path. This vulnerability allows a remote, unauthenticated attacker to query these endpoints and retrieve sensitive configuration data, including cleartext LDAP credentials, SAML configurations, and directory settings. Additionally, the application improperly uses 'Cache-Control: public' headers without a 'Vary: Cookie' header, which can cause downstream reverse proxies or CDNs to cache these sensitive responses and serve them to other unauthenticated users. The issue is categorized under CWE-306 (Missing Authentication for Critical Function) and CWE-524 (Use of Cache Containing Sensitive Information). Users should upgrade to version 3.93.5 or later to remediate these risks.
Affected products
- Tenable Identity Exposure < 3.93.5
Timeline
- 2026-06-23: disclosed
- 2026-06-23: advisory