Vulnerabilities (CVE)

Filtered by vendor Tenable Subscribe
Filtered by product Identity Exposure
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-13007 1 Tenable 1 Identity Exposure 2026-08-19 N/A 7.5 HIGH
Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive application configuration data including cleartext LDAP credentials, SAML configuration, user accounts, and directory settings to unauthenticated remote attackers. Affected responses are served with Cache-Control: public headers and without Vary: Cookie, allowing reverse proxies and CDNs to cache and serve sensitive data to unauthenticated users even after authentication is applied.
CVE-2024-3232 1 Tenable 1 Identity Exposure 2026-06-17 N/A 7.6 HIGH
A formula injection vulnerability exists in Tenable Identity Exposure where an authenticated remote attacker with administrative privileges could manipulate application form fields in order to trick another administrator into executing CSV payloads. - CVE-2024-3232
CVE-2024-1683 1 Tenable 1 Identity Exposure 2026-06-17 N/A 7.3 HIGH
A DLL injection vulnerability exists where an authenticated, low-privileged local attacker could modify application files on the TIE Secure Relay host, which could allow for overriding of the configuration and running of new Secure Relay services.