Impact
A path traversal flaw in Tanium Data Service allows an attacker to supply specially crafted path components that resolve to files outside the intended directory. This can enable unauthorized reading of or overwriting of files on the host where the service runs, potentially exposing sensitive information or altering configuration files. The weakness is classified as CWE‑22, and the CVE description does not indicate additional capabilities beyond the path manipulation.
Affected Systems
All instances of Tanium Data Service are potentially impacted; no specific product versions are listed in the CNA data, so any deployed Tanium Data Service could be vulnerable unless the environment has been verified otherwise.
Risk and Exploitability
The CVSS base score of 6.6 indicates moderate severity. The EPSS score is not reported, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation. The likely attack vector is network‑based if the Tanium Data Service is reachable from untrusted hosts, which would give an attacker a chance to supply a malicious path request. The risk remains moderate due to the potential for data disclosure or inadvertent file modification if an attacker succeeds.
OpenCVE Enrichment