Impact
Based on the description, Tanium has identified a user interface (UI) misrepresentation vulnerability in Tanium Server that can cause critical information to be displayed incorrectly to users. This deficiency could lead to the exposure of information that would otherwise not be released, or users could be misled into making decisions based on inaccurate data. The weakness is classified as a CWE‑451 Information Exposure vulnerability, which compromises the confidentiality of data by providing users with true, never‑before disclosed or inaccurate information.
Affected Systems
Tanium Server is impacted. No specific version range is listed, so all deployments of the Tanium Server services could potentially exhibit this issue until patched.
Risk and Exploitability
The CVSS score of 2.7 indicates a low severity condition, and the EPSS score of less than 1 percent suggests that active exploitation is currently unlikely. The vulnerability is not included in the CISA KEV catalog. Based on the description, the likely attack vector is a user with valid access to the Tanium Server console; remote attackers without UI access are unlikely to benefit directly. Because the flaw only misrepresents already‑exposed data rather than granting unauthorized system access, the overall risk remains limited.
OpenCVE Enrichment