High severity7.5NVD Advisory· Published Jun 23, 2026· Updated Jun 25, 2026
CVE-2026-13007
CVE-2026-13007
Description
Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive application configuration data including cleartext LDAP credentials, SAML configuration, user accounts, and directory settings to unauthenticated remote attackers. Affected responses are served with Cache-Control: public headers and without Vary: Cookie, allowing reverse proxies and CDNs to cache and serve sensitive data to unauthenticated users even after authentication is applied.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.