TAN-2026-050
Tanium addressed a server-side request forgery vulnerability in Threat Response.
Severity: Medium
Base Score: 6.5
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Impact
This vulnerability could allow an authenticated Tanium user with the Threat Response Live Response Destinations Write permission to gain read access to data they should not have access to.
Products Affected
2025H1 Release:
- Threat Response prior to Update 25 (v4.9.454)
2025H2 Release:
- Threat Response prior to Update 15 (v4.12.324)
2026H1 Release:
- Threat Response prior to Update 8 (v4.17.292)
Available Updates
2025H1 Release:
- Update 25 (Threat Response v4.9.454) and later
2025H2 Release:
- Update 15 (Threat Response v4.12.324) and later
2026H1 Release:
- Update 8 (Threat Response v4.17.292) and later
Workaround and Mitigations
None.
Acknowledgements
None.