Description
Tanium addressed a User Interface (UI) Misrepresentation of Critical Information vulnerability in Tanium Server.
Published: 2026-07-21
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the description, Tanium has identified a user interface (UI) misrepresentation vulnerability in Tanium Server that can cause critical information to be displayed incorrectly to users. This deficiency could lead to the exposure of information that would otherwise not be released, or users could be misled into making decisions based on inaccurate data. The weakness is classified as a CWE‑451 Information Exposure vulnerability, which compromises the confidentiality of data by providing users with true, never‑before disclosed or inaccurate information.

Affected Systems

Tanium Server is impacted. No specific version range is listed, so all deployments of the Tanium Server services could potentially exhibit this issue until patched.

Risk and Exploitability

The CVSS score of 2.7 indicates a low severity condition, and the EPSS score of less than 1 percent suggests that active exploitation is currently unlikely. The vulnerability is not included in the CISA KEV catalog. Based on the description, the likely attack vector is a user with valid access to the Tanium Server console; remote attackers without UI access are unlikely to benefit directly. Because the flaw only misrepresents already‑exposed data rather than granting unauthorized system access, the overall risk remains limited.

Generated by OpenCVE AI on July 30, 2026 at 16:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Tanium Server update referenced in the vendor advisory (https://security.tanium.com/TAN-2026-017) to correct UI rendering errors and address the CWE‑451 vulnerability.
  • Enforce strict role‑based access controls to limit user interface exposure and mitigate the CWE‑451 information exposure risk.
  • Monitor Tanium community and vendor advisories for any follow‑up patches or additional mitigations addressing CWE‑451.

Generated by OpenCVE AI on July 30, 2026 at 16:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Thu, 23 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Tanium
Tanium tanium Server
Vendors & Products Tanium
Tanium tanium Server

Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Tanium addressed a User Interface (UI) Misrepresentation of Critical Information vulnerability in Tanium Server.
Title Tanium addressed a User Interface (UI) Misrepresentation of Critical Information vulnerability in Tanium Server.
Weaknesses CWE-451
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Tanium Tanium Server
cve-icon MITRE

Status: PUBLISHED

Assigner: Tanium

Published:

Updated: 2026-07-22T19:40:54.065Z

Reserved: 2026-06-10T17:57:47.060Z

Link: CVE-2026-11925

cve-icon Vulnrichment

Updated: 2026-07-22T19:31:53.124Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T16:45:04Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information