Skip to content

TAN-2026-031

Tanium addressed an improper access controls vulnerability in Tanium Server.

Severity: Medium

Base Score: 4.3

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Impact

This vulnerability could allow an authenticated Tanium user to perform a denial of service attack against the Tanium Server.

Products Affected

2025H1 Release:

  • Tanium Server prior to Update 21 (v7.7.3 to v7.7.3.8298)

2025H2 Release:

  • Tanium Server prior to Update 11 (v7.8.2 to v7.8.2.1198)

2026H1 Release:

  • Tanium Server prior to Update 3 (v7.8.4 to v7.8.4.1327)

Available Updates

2025H1 Release:

  • Update 21 (Tanium Server v7.7.3.8298) and later

2025H2 Release:

  • Update 11 (Tanium Server v7.8.2.1198) and later

2026H1 Release:

  • Update 3 (Tanium Server v7.8.4.1327) and later

Workaround and Mitigations

None.

Acknowledgements

None.