Description
Tanium addressed an information disclosure vulnerability in Connect.
Published: 2026-07-21
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an information disclosure flaw in Tanium Connect, classified under CWE-214. Attackers could retrieve sensitive data that is not intended to be exposed, potentially compromising confidentiality. The description does not state the extent of data that can be extracted, but the impact is limited to the data that Tanium Connect stores or passes.

Affected Systems

Tanium Connect is affected. No specific version information is provided by the CNA, so all installations of Tanium Connect are potentially vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 4.4 indicates moderate risk, and the EPSS score of less than 1% shows that there is a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is through local or network access to the Connect service, but this is inferred rather than stated in the public advisory.

Generated by OpenCVE AI on July 30, 2026 at 16:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and deploy the latest Tanium Connect release that contains the fix.
  • If a fix is not yet available, restrict network access to Tanium Connect servers to prevent unauthorized parties from connecting.
  • Continuously monitor Tanium logs for signs of data leaks or unauthorized access attempts.

Generated by OpenCVE AI on July 30, 2026 at 16:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Thu, 23 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
First Time appeared Tanium
Tanium connect
Vendors & Products Tanium
Tanium connect

Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Tanium addressed an information disclosure vulnerability in Connect.
Title Tanium addressed an information disclosure vulnerability in Connect.
Weaknesses CWE-214
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Tanium

Published:

Updated: 2026-07-22T19:40:47.897Z

Reserved: 2026-06-12T17:05:55.702Z

Link: CVE-2026-12139

cve-icon Vulnrichment

Updated: 2026-07-22T19:31:54.561Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T16:45:04Z

Weaknesses
  • CWE-214

    Invocation of Process Using Visible Sensitive Information