Description
Tanium addressed an improper access controls vulnerability in Tanium Server.
Published: 2026-09-09
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Improper Access Control
Action: Apply Update
AI Analysis

Impact

Tanium Server is subject to an improper access control flaw that allows users to access resources or operations they should not be permitted to use. The weakness is defined as CWE‑863 and translates into a potential elevation of privileges or unauthorized data access within the Tanium deployment. The CVSS score of 4.3 reflects a low severity overall, but the impact can be significant if an attacker coerces a user or gains access to a privileged account.

Affected Systems

The affected product is Tanium Server by Tanium. No specific version ranges are mentioned, suggesting that the issue could apply to multiple or all releases until a patch is issued.

Risk and Exploitability

The CVSS score of 4.3 indicates a modest impact, and No EPSS score is available to gauge current exploitation hotness. The vulnerability is not listed in the CISA KEV catalog, which reduces the likelihood of emerging public exploits. The report does not specify an attack vector; based on typical access‑control weaknesses, the most likely vectors are local privilege escalation or remote exploitation over a network interface that is inadequately protected. Users should treat this as a low‑to‑moderate risk until a vendor patch is applied.

Generated by OpenCVE AI on September 9, 2026 at 04:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Review Tanium Server permissions to enforce least privilege for all user accounts
  • Check the Tanium security site or contact support for the latest patch and apply it immediately
  • Restrict network exposure of Tanium Server to internal, trusted hosts and monitor logs for unauthorized access attempts

Generated by OpenCVE AI on September 9, 2026 at 04:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Thu, 10 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Tanium
Tanium tanium Server
Vendors & Products Tanium
Tanium tanium Server

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Description Tanium addressed an improper access controls vulnerability in Tanium Server.
Title Tanium addressed an improper access controls vulnerability in Tanium Server.
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Tanium Tanium Server
cve-icon MITRE

Status: PUBLISHED

Assigner: Tanium

Published:

Updated: 2026-09-09T16:10:30.929Z

Reserved: 2026-07-06T18:09:55.476Z

Link: CVE-2026-14892

cve-icon Vulnrichment

Updated: 2026-09-09T16:04:39.223Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-09T03:17:23.037

Modified: 2026-09-09T17:17:16.617

Link: CVE-2026-14892

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:15:06Z

Weaknesses