VYPR
Medium severity4.3NVD Advisory· Published Feb 26, 2025· Updated Apr 15, 2026

CVE-2025-1091

CVE-2025-1091

Description

CVE-2025-1091: An authenticated user can download IOA script and configuration files from Tenable Identity Exposure if the URL is known.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CVE-2025-1091: An authenticated user can download IOA script and configuration files from Tenable Identity Exposure if the URL is known.

Vulnerability

Overview

CVE-2025-1091 is a broken authorization vulnerability in Tenable Identity Exposure. Any authenticated user, regardless of their privilege level, can download IOA (Identity Object Awareness) script and configuration files if they know the URL of those files. The root cause is an insufficient authorization check that fails to restrict access to these sensitive resources based on user roles.

Exploitation

Exploitation requires the attacker to be an authenticated user of the Tenable Identity Exposure platform. The attack does not require any special privileges; any account with valid credentials can be used. The attacker must know or guess the specific URL path where IOA scripts and configuration files are stored. This is a low-complexity attack that can be performed over the network, as described in the official advisory [1].

Impact

Successful exploitation allows an attacker to download IOA scripts and configuration files, which may contain sensitive information about the identity exposure setup. This could aid in further attacks or reveal internal configuration details. The CVSS v3 base score is 4.3 (Medium), indicating moderate severity due to the prerequisites of authentication and knowledge of the URL.

Mitigation

Tenable has addressed this vulnerability in Identity Exposure version 3.77.9. Users should upgrade to this version or later to remediate the issue. No workarounds are mentioned in the advisory [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.