Skip to content

TAN-2026-022

Tanium addressed an unauthorized code execution vulnerability in Enforce.

Severity: High

Base Score: 7.0

Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Impact

This vulnerability could allow an attacker with access to a system running the Tanium Client to achieve local privilege escalation when a maliciously-named file already present in antivirus quarantine is processed during a remediation action.

Products Affected

2025H1 Release:

  • Enforce prior to Update 24 (v2.9 to v2.9.718)

2025H2 Release:

  • Enforce prior to Update 14 (v2.10 to v2.10.760)

2026H1 Release:

  • Enforce prior to Update 7 (v3.0 to v3.0.346)

Available Updates

2025H1 Release:

  • Update 24 (Enforce v2.9.718) and later

2025H2 Release:

  • Update 14 (Enforce v2.10.760) and later

2026H1 Release:

  • Update 7 (Enforce v3.0.346) and later

Workaround and Mitigations

None.

Acknowledgements

None.