Description
Tanium addressed an improper access controls vulnerability in Threat Response.
Published: 2026-09-16
Score: 3.8 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access / Privilege Escalation
Action: Assess Impact
AI Analysis

Impact

The vulnerability is an improper access control flaw in Tanium Threat Response that can allow an attacker to bypass expected authorization checks. The primary impact is the potential for an attacker to gain unauthorized access or elevate privileges within the system, which could lead to unauthorized data access, modification, or other malicious activity. The weakness is classified under CWE-862, indicating that the system fails to enforce appropriate access permissions.

Affected Systems

Tanium Threat Response is affected. No specific version information is provided, so all installations of Tanium Threat Response are potentially impacted until a vendor-released fix or mitigation strategy is applied.

Risk and Exploitability

The CVSS score of 3.8 indicates low severity, and the EPSS score of less than 1% suggests that exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred to be remote via the Threat Response interface or API, but the description does not explicitly specify the required conditions or environment for exploitation. Therefore, the risk is considered low but not negligible, and monitoring for unauthorized access attempts is recommended.

Generated by OpenCVE AI on September 18, 2026 at 01:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Verify that Tanium Threat Response is installed or in use in your environment.
  • Check with Tanium or consult their security advisory for a patch or update that addresses the improper access control flaw, and apply the fix as soon as it becomes available.
  • If no patch is immediately available, implement strict access controls on Threat Response accounts, ensuring only authorized personnel have the necessary permissions.

Generated by OpenCVE AI on September 18, 2026 at 01:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 18 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Tanium
Tanium threat Response
Vendors & Products Tanium
Tanium threat Response

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description Tanium addressed an improper access controls vulnerability in Threat Response.
Title Tanium addressed an improper access controls vulnerability in Threat Response.
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 3.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Tanium Threat Response
cve-icon MITRE

Status: PUBLISHED

Assigner: Tanium

Published:

Updated: 2026-09-17T16:11:08.311Z

Reserved: 2026-09-08T18:00:46.024Z

Link: CVE-2026-87026

cve-icon Vulnrichment

Updated: 2026-09-17T16:10:46.857Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T20:17:37.757

Modified: 2026-09-18T19:19:49.643

Link: CVE-2026-87026

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T02:30:06Z

Weaknesses