Description
Tanium addressed a SQL injection vulnerability in Asset.
Published: 2026-09-16
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Data Compromise
Action: Immediate Patch
AI Analysis

Impact

Tanium Asset contains a SQL injection vulnerability classified as CWE‑89. The CVE description states only that a SQL injection flaw exists; no explicit impact details are provided. By definition, such a flaw could allow unauthorized manipulation or disclosure of data stored in the underlying database.

Affected Systems

The affected product is Tanium Asset. No specific version information is included in the advisory, so any installation of Tanium Asset that has not applied the vendor’s update could be vulnerable.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity rating. The EPSS score of less than 1% suggests a low likelihood of exploitation at the time of assessment. The vulnerability is not listed in the CISA KEV catalog, implying no confirmed active exploits. The likely attack vector is inferred to be remote via a web interface or API that accepts user-controlled input, based on the nature of SQL injection vulnerabilities and the typical operation of Tanium Asset.

Generated by OpenCVE AI on September 17, 2026 at 22:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑released patch for Tanium Asset as published in the security advisory.
  • If a patch is not yet available, restrict or sanitize user-controllable inputs that are used in SQL statements, or deploy a WAF rule to block typical SQL injection payloads.
  • Continuously monitor database activity logs for anomalous queries that could indicate exploitation attempts.

Generated by OpenCVE AI on September 17, 2026 at 22:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 18 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Tanium
Tanium asset
Vendors & Products Tanium
Tanium asset

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description Tanium addressed a SQL injection vulnerability in Asset.
Title Tanium addressed a SQL injection vulnerability in Asset.
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Tanium

Published:

Updated: 2026-09-17T15:00:56.412Z

Reserved: 2026-09-08T17:48:38.364Z

Link: CVE-2026-87024

cve-icon Vulnrichment

Updated: 2026-09-17T15:00:30.235Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T20:17:37.643

Modified: 2026-09-18T19:19:49.643

Link: CVE-2026-87024

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T01:45:16Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')