Impact
Tanium Server is subject to an improper access control flaw that allows users to access resources or operations they should not be permitted to use. The weakness is defined as CWE‑863 and translates into a potential elevation of privileges or unauthorized data access within the Tanium deployment. The CVSS score of 4.3 reflects a low severity overall, but the impact can be significant if an attacker coerces a user or gains access to a privileged account.
Affected Systems
The affected product is Tanium Server by Tanium. No specific version ranges are mentioned, suggesting that the issue could apply to multiple or all releases until a patch is issued.
Risk and Exploitability
The CVSS score of 4.3 indicates a modest impact, and No EPSS score is available to gauge current exploitation hotness. The vulnerability is not listed in the CISA KEV catalog, which reduces the likelihood of emerging public exploits. The report does not specify an attack vector; based on typical access‑control weaknesses, the most likely vectors are local privilege escalation or remote exploitation over a network interface that is inadequately protected. Users should treat this as a low‑to‑moderate risk until a vendor patch is applied.
OpenCVE Enrichment