Description
Tanium addressed a server-side request forgery vulnerability in Enforce.
Published: 2026-09-09
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery enabling unauthorized network requests
Action: Apply Patch
AI Analysis

Impact

Tanium Enforce contains a server‑side request forgery flaw, classified as CWE‑918. This weakness allows an attacker to instruct the Enforce server to fetch arbitrary resources over HTTP or other protocols, potentially exposing internal data or facilitating further compromise. The primary impact is that an adversary could gain unintended access to internal services, retrieve sensitive information, or pivot within the network.

Affected Systems

The vulnerability affects Tanium Enforce. No specific affected versions are listed in the advisory, so all deployed instances of Enforce should be considered vulnerable until a patch is confirmed installed.

Risk and Exploitability

The CVSS score of 7.7 indicates high severity, and the lack of an EPSS score or KEV listing suggests the vulnerability has not yet been widely exploited but remains a serious risk. Attackers likely need network access to the compromised Enforce instance and may use the SSRF path to reach internal resources that are otherwise unreachable from the outside. Without mitigation, the flaw could be utilized to read or modify data on internal services, bypassing normal access controls.

Generated by OpenCVE AI on September 9, 2026 at 04:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • If Tanium has issued a patch for Enforce, upgrade to the latest version immediately.
  • Configure the Enforce server’s outbound network policy to allow requests only to explicitly trusted destinations, blocking all other networks.
  • Enable and review logging for outbound requests originating from Enforce, and investigate any unexpected or suspicious traffic.

Generated by OpenCVE AI on September 9, 2026 at 04:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 16 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:tanium:enforce:*:*:*:*:*:*:*:*

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Tanium
Tanium enforce
Vendors & Products Tanium
Tanium enforce

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Description Tanium addressed a server-side request forgery vulnerability in Enforce.
Title Tanium addressed a server-side request forgery vulnerability in Enforce.
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Tanium

Published:

Updated: 2026-09-09T16:10:29.632Z

Reserved: 2026-09-08T19:30:17.199Z

Link: CVE-2026-87084

cve-icon Vulnrichment

Updated: 2026-09-09T16:04:19.815Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T03:17:27.070

Modified: 2026-09-16T15:25:15.347

Link: CVE-2026-87084

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:48:10Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)