TAN-2026-036
Tanium addressed a server-side request forgery vulnerability in Enforce.
Severity: High
Base Score: 7.7
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Impact
This vulnerability could allow an authenticated Tanium user with the enforce policy write permission to gain read-only access to data they should not have access to.
Products Affected
2025H1 Release:
- Enforce prior to Update 24 (v2.9 to v2.9.718)
2025H2 Release:
- Enforce prior to Update 14 (v2.10 to v2.10.760)
2026H1 Release:
- Enforce prior to Update 7 (v3.0 to v3.0.346)
Available Updates
2025H1 Release:
- Update 24 (Enforce v2.9.718) and later
2025H2 Release:
- Update 14 (Enforce v2.10.760) and later
2026H1 Release:
- Update 7 (Enforce v3.0.346) and later
Workaround and Mitigations
None.
Acknowledgements
None.