Description
Tanium addressed a path traversal vulnerability in Tanium Data Service.
Published: 2026-09-09
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized File Access via Path Traversal
Action: Apply Patch
AI Analysis

Impact

A path traversal flaw in Tanium Data Service allows an attacker to supply specially crafted path components that resolve to files outside the intended directory. This can enable unauthorized reading of or overwriting of files on the host where the service runs, potentially exposing sensitive information or altering configuration files. The weakness is classified as CWE‑22, and the CVE description does not indicate additional capabilities beyond the path manipulation.

Affected Systems

All instances of Tanium Data Service are potentially impacted; no specific product versions are listed in the CNA data, so any deployed Tanium Data Service could be vulnerable unless the environment has been verified otherwise.

Risk and Exploitability

The CVSS base score of 6.6 indicates moderate severity. The EPSS score is not reported, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation. The likely attack vector is network‑based if the Tanium Data Service is reachable from untrusted hosts, which would give an attacker a chance to supply a malicious path request. The risk remains moderate due to the potential for data disclosure or inadvertent file modification if an attacker succeeds.

Generated by OpenCVE AI on September 9, 2026 at 05:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Tanium update that addresses the path traversal vulnerability as outlined in Tanium's advisory.
  • Restrict external access to the Tanium Data Service so that only trusted internal networks can reach it, enforcing least‑privilege network segmentation.
  • Configure the operating system file permissions on the directories used by Tanium Data Service to deny write access to untrusted users and processes, reducing the impact of any remaining path traversal attempts.

Generated by OpenCVE AI on September 9, 2026 at 05:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Tanium
Tanium tanium Data Service
Vendors & Products Tanium
Tanium tanium Data Service

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Description Tanium addressed a path traversal vulnerability in Tanium Data Service.
Title Tanium addressed a path traversal vulnerability in Tanium Data Service.
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Tanium Tanium Data Service
cve-icon MITRE

Status: PUBLISHED

Assigner: Tanium

Published:

Updated: 2026-09-09T16:10:31.974Z

Reserved: 2026-07-02T18:24:41.863Z

Link: CVE-2026-14505

cve-icon Vulnrichment

Updated: 2026-09-09T16:04:58.011Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-09T03:17:22.913

Modified: 2026-09-09T17:17:16.490

Link: CVE-2026-14505

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:02:52Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')