Unrated severityNVD Advisory· Published Jun 23, 2026· Updated Jun 23, 2026
Insecure Public Caching on REST API Endpoints in Tenable Identity Exposure
CVE-2026-13007
Description
Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive application configuration data including cleartext LDAP credentials, SAML configuration, user accounts, and directory settings to unauthenticated remote attackers. Affected responses are served with Cache-Control: public headers and without Vary: Cookie, allowing reverse proxies and CDNs to cache and serve sensitive data to unauthenticated users even after authentication is applied.
Affected products
1Patches
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.tenable.com/security/research/tns-2026-16mitrevendor-advisory
News mentions
0No linked articles in our index yet.