Description
Tanium addressed an information disclosure vulnerability in Discover.
Published: 2026-09-16
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in Tanium Discover, allowing an attacker to obtain restricted information through improper access controls. An attacker who can reach the Discover interface may view sensitive data that should be restricted. The weakness is classified as CWE‑200. The impact is a compromise of confidentiality, with no evidence of code execution or denial of service.

Affected Systems

The flaw affects the Tanium Discover product. No specific version range is provided in the advisory, so any deployment using Tanium Discover remains potentially vulnerable until verified that the fix is applied.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests a very low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, implying it has no known active exploits. Attackers who can access the Discover interface would need valid credentials or local network access, so the attack vector is likely network-based. Overall risk remains moderate but with low exploitation likelihood.

Generated by OpenCVE AI on September 17, 2026 at 21:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy the Tanium Discover patch or upgrade to the latest version as recommended by Tanium.
  • Ensure that only authorized users have access to the Discover service by applying role‑based access controls and network segmentation.
  • Monitor for suspicious activity on the Discover interface and verify that the patch has been successfully applied.

Generated by OpenCVE AI on September 17, 2026 at 21:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 18 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Tanium
Tanium discover
Vendors & Products Tanium
Tanium discover

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description Tanium addressed an information disclosure vulnerability in Discover.
Title Tanium addressed an information disclosure vulnerability in Discover.
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Tanium

Published:

Updated: 2026-09-17T15:02:07.566Z

Reserved: 2026-09-08T19:20:27.480Z

Link: CVE-2026-87076

cve-icon Vulnrichment

Updated: 2026-09-17T15:02:00.416Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T20:17:37.867

Modified: 2026-09-18T19:19:49.643

Link: CVE-2026-87076

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T01:45:16Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor