Skip to content

TAN-2026-044

Tanium addressed a path traversal vulnerability in Tanium Data Service.

Severity: Medium

Base Score: 6.6

Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Impact

This vulnerability could allow an authenticated Tanium user with the "Data Collection Pipeline Write Override" permission to write arbitrary files on the Tanium Module Server.

Products Affected

2026H1 Release:

  • Tanium Data Service prior to Update 4 (v4.2 to v4.2.345)

Available Updates

2026H1 Release:

  • Update 4 (Tanium Data Service v4.2.345) and later

Workaround and Mitigations

None.

Acknowledgements

None.