CVE-2026-13007

Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive application configuration data including cleartext LDAP credentials, SAML configuration, user accounts, and directory settings to unauthenticated remote attackers. Affected responses are served with Cache-Control: public headers and without Vary: Cookie, allowing reverse proxies and CDNs to cache and serve sensitive data to unauthenticated users even after authentication is applied.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:tenable:identity_exposure:*:*:*:*:on-premises:*:*:*

History

No history.

Information

Published : 2026-06-23 17:16

Updated : 2026-08-19 14:18


NVD link : CVE-2026-13007

Mitre link : CVE-2026-13007

CVE.ORG link : CVE-2026-13007


JSON object : View

Products Affected

tenable

  • identity_exposure
CWE
CWE-306

Missing Authentication for Critical Function

CWE-524

Use of Cache Containing Sensitive Information