TAN-2026-018
Tanium addressed an information disclosure vulnerability in Connect.
Severity: Medium
Base Score: 4.4
Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Impact
This vulnerability could allow an attacker with access to the system running the Tanium Module Server to obtain the SMB credentials used with the Connect SMB destination.
Products Affected
2025H1 Release:
- Connect prior to Update MR20 (v5.29.251)
2025H2 Release:
- Connect prior to Update MR10 (v5.37.156)
2026H1 Release:
- Connect prior to Update MR2 (v5.47.112)
Available Updates
2025H1 Release:
- Update MR20 (Connect v5.29.251) and later
2025H2 Release:
- Update MR10 (Connect v5.37.156) and later
2026H1 Release:
- Update MR2 (Connect v5.47.112) and later
In addition to updating to the latest version of Connect, users should consider the following mitigation steps: - Rotate the credential for any Connect SMB Destinations.
Workaround and Mitigations
None.
Acknowledgements
None.