Skip to content

TAN-2026-050

Tanium addressed a server-side request forgery vulnerability in Threat Response.

Severity: Medium

Base Score: 6.5

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Impact

This vulnerability could allow an authenticated Tanium user with the Threat Response Live Response Destinations Write permission to gain read access to data they should not have access to.

Products Affected

2025H1 Release:

  • Threat Response prior to Update 25 (v4.9.454)

2025H2 Release:

  • Threat Response prior to Update 15 (v4.12.324)

2026H1 Release:

  • Threat Response prior to Update 8 (v4.17.292)

Available Updates

2025H1 Release:

  • Update 25 (Threat Response v4.9.454) and later

2025H2 Release:

  • Update 15 (Threat Response v4.12.324) and later

2026H1 Release:

  • Update 8 (Threat Response v4.17.292) and later

Workaround and Mitigations

None.

Acknowledgements

None.