Description
Tanium addressed a SQL injection vulnerability in Asset.
Published: 2026-09-16
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection in Tanium Asset component
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a classic SQL injection flaw that allows a privileged attacker to manipulate database queries within Tanium's Asset service. By injecting malicious SQL, an attacker could read, modify, or delete data stored by Asset, thereby compromising confidentiality, integrity, and possibly disrupting availability if critical data is altered. The CVSS score of 7.2 reflects these potential impacts. The vulnerability is tied to CWE-89.

Affected Systems

Tanium Product Suite – Asset component. No specific affected versions are listed, so all deployments using the Asset service are potentially vulnerable until patched.

Risk and Exploitability

The EPSS score of less than 1% indicates a low probability that this flaw is actively exploited in the wild. The vulnerability is not listed in CISA’s KEV catalog, which further suggests limited exploitation. The likely attack vector is remote, as the injection would be triggered through network-accessible Asset interfaces. An attacker would need to provide crafted input to the Asset service, which may require network connectivity and, possibly, authentication depending on deployment. Overall, the risk is moderate because of the CVSS score, but the low EPSS score and absence from KEV reduce the urgency compared to higher‑impact or widely exploited flaws.

Generated by OpenCVE AI on September 17, 2026 at 22:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch for Tanium Asset as soon as it is available.
  • Immediately review and tighten database permissions, ensuring Asset uses the least privilege account for database access.
  • Disable or restrict external API access to Asset that accepts untrusted input until the patch is applied.
  • Monitor Asset logs for unusual SQL query patterns and investigate promptly.

Generated by OpenCVE AI on September 17, 2026 at 22:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 18 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Tanium
Tanium asset
Vendors & Products Tanium
Tanium asset

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description Tanium addressed a SQL injection vulnerability in Asset.
Title Tanium addressed a SQL injection vulnerability in Asset.
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Tanium

Published:

Updated: 2026-09-17T15:02:33.694Z

Reserved: 2026-09-08T15:47:56.959Z

Link: CVE-2026-86865

cve-icon Vulnrichment

Updated: 2026-09-17T15:02:29.054Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T20:17:37.153

Modified: 2026-09-18T19:19:49.643

Link: CVE-2026-86865

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T06:30:05Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')