TAN-2026-044
Tanium addressed a path traversal vulnerability in Tanium Data Service.
Severity: Medium
Base Score: 6.6
Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Impact
This vulnerability could allow an authenticated Tanium user with the "Data Collection Pipeline Write Override" permission to write arbitrary files on the Tanium Module Server.
Products Affected
2026H1 Release:
- Tanium Data Service prior to Update 4 (v4.2 to v4.2.345)
Available Updates
2026H1 Release:
- Update 4 (Tanium Data Service v4.2.345) and later
Workaround and Mitigations
None.
Acknowledgements
None.