Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-13007

Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive application configuration data including cleartext LDAP credentials, SAML configuration, user accounts, and directory settings to unauthenticated remote attackers. Affected responses are served with Cache-Control: public headers and without Vary: Cookie, allowing reverse proxies and CDNs to cache and serve sensitive data to unauthenticated users even after authentication is applied.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 46.7%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2026-13007


Contact Us

Shodan ® - All rights reserved