Impact
The disclosed flaw involves improper access controls within Tanium's Threat Response module, allowing an authenticated user to access data or perform actions beyond their assigned permissions. The vulnerability is classified as CWE‑639, indicating an improper authorization issue.
Affected Systems
Deployments of Tanium Threat Response are affected; specific version details are not provided in the advisory. Administrators should review all installations of the Threat Response product and verify whether the latest security update referenced in the Tanium advisory has been applied.
Risk and Exploitability
The CVSS score of 6.3 denotes a medium severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in CISA's KEV catalog. The attack vector is inferred to be local or domain‑bound, requiring authenticated access to the Threat Response interface or API, and the lack of proof of exploitation reduces immediate urgency.
OpenCVE Enrichment