Skip to content

TAN-2026-036

Tanium addressed a server-side request forgery vulnerability in Enforce.

Severity: High

Base Score: 7.7

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Impact

This vulnerability could allow an authenticated Tanium user with the enforce policy write permission to gain read-only access to data they should not have access to.

Products Affected

2025H1 Release:

  • Enforce prior to Update 24 (v2.9 to v2.9.718)

2025H2 Release:

  • Enforce prior to Update 14 (v2.10 to v2.10.760)

2026H1 Release:

  • Enforce prior to Update 7 (v3.0 to v3.0.346)

Available Updates

2025H1 Release:

  • Update 24 (Enforce v2.9.718) and later

2025H2 Release:

  • Update 14 (Enforce v2.10.760) and later

2026H1 Release:

  • Update 7 (Enforce v3.0.346) and later

Workaround and Mitigations

None.

Acknowledgements

None.