Description
Tanium addressed an insertion of sensitive information into log file vulnerability in Trends.
Published: 2026-02-19
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Potential Disclosure of Sensitive Information
Action: Apply Patch
AI Analysis

Impact

Tanium reported that certain log files within the Trends component may contain unsolicited sensitive information, creating a confidentiality risk. The underlying weakness is logged as a CWE‑532 condition, reflecting that logs should not contain personally or system‑sensitive data. When triggered, the compromised logs can reveal confidential data to an attacker who can read the files, potentially enabling information disclosure. The vulnerability does not affect system integrity or availability directly but permits unauthorized access to data that should remain private.

Affected Systems

The vulnerability impacts Tanium’s Trends product, specifically Service Trends releases 3.10.19 and 3.11.77, along with any later releases that exhibit the same logging behavior. End‑users should verify the exact version installed in their environment by consulting the product version information and ensure that their system is not running an affected release.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while an EPSS score of less than 1% reflects a very low probability of exploitation at the time of analysis. The issue is not cataloged in the CISA KEV list, suggesting no publicly known exploits currently exist. Based on the description, the attack vector is not explicitly documented; it is inferred that an attacker would need the ability to read the log files or otherwise trigger log writes, implying either local or remote privilege within the system. Consequently, the risk level remains moderate but requires timely mitigation to prevent accidental data leakage.

Generated by OpenCVE AI on April 17, 2026 at 17:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch or upgrade to a version of Tanium Service Trends that includes the fix for the log injection issue.
  • Modify log configuration to exclude or mask sensitive data so that passwords, personal information, or system credentials are not recorded.
  • Regularly audit log files to ensure no confidential data is being captured and adjust monitoring to detect unusual log content.

Generated by OpenCVE AI on April 17, 2026 at 17:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 02 Mar 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 28 Feb 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Tanium trends
CPEs cpe:2.3:a:tanium:trends:*:*:*:*:*:*:*:*
Vendors & Products Tanium trends

Thu, 19 Feb 2026 23:30:00 +0000

Type Values Removed Values Added
Description Tanium addressed an insertion of sensitive information into log file vulnerability in Trends.
Title Tanium addressed an insertion of sensitive information into log file vulnerability in Trends.
First Time appeared Tanium
Tanium service Trends
Weaknesses CWE-532
CPEs cpe:2.3:a:tanium:service_trends:3.10.19:*:*:*:*:*:*:*
cpe:2.3:a:tanium:service_trends:3.11.77:*:*:*:*:*:*:*
Vendors & Products Tanium
Tanium service Trends
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Tanium Service Trends Trends
cve-icon MITRE

Status: PUBLISHED

Assigner: Tanium

Published:

Updated: 2026-03-02T15:50:54.033Z

Reserved: 2026-01-21T16:30:45.783Z

Link: CVE-2026-1292

cve-icon Vulnrichment

Updated: 2026-03-02T15:50:42.388Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-20T00:16:14.520

Modified: 2026-02-27T23:48:33.440

Link: CVE-2026-1292

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-17T17:45:24Z

Weaknesses