Skip to content

TAN-2026-018

Tanium addressed an information disclosure vulnerability in Connect.

Severity: Medium

Base Score: 4.4

Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Impact

This vulnerability could allow an attacker with access to the system running the Tanium Module Server to obtain the SMB credentials used with the Connect SMB destination.

Products Affected

2025H1 Release:

  • Connect prior to Update MR20 (v5.29.251)

2025H2 Release:

  • Connect prior to Update MR10 (v5.37.156)

2026H1 Release:

  • Connect prior to Update MR2 (v5.47.112)

Available Updates

2025H1 Release:

  • Update MR20 (Connect v5.29.251) and later

2025H2 Release:

  • Update MR10 (Connect v5.37.156) and later

2026H1 Release:

  • Update MR2 (Connect v5.47.112) and later

In addition to updating to the latest version of Connect, users should consider the following mitigation steps: - Rotate the credential for any Connect SMB Destinations.

Workaround and Mitigations

None.

Acknowledgements

None.