CVE-2026-13007
EUVD-2026-3848723.06.2026, 17:16
Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive application configuration data including cleartext LDAP credentials, SAML configuration, user accounts, and directory settings to unauthenticated remote attackers. Affected responses are served with Cache-Control: public headers and without Vary: Cookie, allowing reverse proxies and CDNs to cache and serve sensitive data to unauthenticated users even after authentication is applied.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| tenable | identity_exposure | 𝑥 < 3.93.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration