TAN-2026-031
Tanium addressed an improper access controls vulnerability in Tanium Server.
Severity: Medium
Base Score: 4.3
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Impact
This vulnerability could allow an authenticated Tanium user to perform a denial of service attack against the Tanium Server.
Products Affected
2025H1 Release:
- Tanium Server prior to Update 21 (v7.7.3 to v7.7.3.8298)
2025H2 Release:
- Tanium Server prior to Update 11 (v7.8.2 to v7.8.2.1198)
2026H1 Release:
- Tanium Server prior to Update 3 (v7.8.4 to v7.8.4.1327)
Available Updates
2025H1 Release:
- Update 21 (Tanium Server v7.7.3.8298) and later
2025H2 Release:
- Update 11 (Tanium Server v7.8.2.1198) and later
2026H1 Release:
- Update 3 (Tanium Server v7.8.4.1327) and later
Workaround and Mitigations
None.
Acknowledgements
None.