Description
Tanium addressed an unauthorized code execution vulnerability in Enforce.
Published: 2026-09-09
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Tanium Enforce contains an unauthorized code execution vulnerability that allows an attacker to run arbitrary code. This flaw is identified as CWE‑78 and can potentially compromise system confidentiality, integrity, and availability by enabling malicious operations. The impact is a full loss of control over affected systems if exploited.

Affected Systems

The vulnerability affects Tanium Enforce. Specific affected product versions are not disclosed in the available data.

Risk and Exploitability

The CVSS score of 7.0 indicates a high severity, although an EPSS score is unavailable. The vulnerability is not listed in the CISA KEV catalog. The attack vector is not explicitly provided in the advisory; based on the nature of the flaw it is inferred that it could be exploitable remotely or locally, depending on the configuration of Enforce. Without a publicly disclosed exploitation technique, the likelihood remains uncertain but the high CVSS justifies proactive mitigation.

Generated by OpenCVE AI on September 9, 2026 at 04:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Tanium Enforce patch or upgrade to the version that addresses the code execution flaw.
  • Restrict network access to Enforce endpoints to limit potential attackers.
  • Configure monitoring to detect anomalous execution attempts or unauthorized code changes in adherence to CWE‑78 best practices.

Generated by OpenCVE AI on September 9, 2026 at 04:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 16 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:tanium:enforce:*:*:*:*:*:*:*:*

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Tanium
Tanium enforce
Vendors & Products Tanium
Tanium enforce

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Description Tanium addressed an unauthorized code execution vulnerability in Enforce.
Title Tanium addressed an unauthorized code execution vulnerability in Enforce.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Tanium

Published:

Updated: 2026-09-09T16:10:32.275Z

Reserved: 2026-09-08T19:46:13.057Z

Link: CVE-2026-87088

cve-icon Vulnrichment

Updated: 2026-09-09T16:05:04.405Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T03:17:27.183

Modified: 2026-09-16T15:25:19.183

Link: CVE-2026-87088

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:51:16Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')