Description
Tanium addressed an improper access controls vulnerability in Threat Response.
Published: 2026-09-16
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via Improper Access Control
Action: Patch
AI Analysis

Impact

The disclosed flaw involves improper access controls within Tanium's Threat Response module, allowing an authenticated user to access data or perform actions beyond their assigned permissions. The vulnerability is classified as CWE‑639, indicating an improper authorization issue.

Affected Systems

Deployments of Tanium Threat Response are affected; specific version details are not provided in the advisory. Administrators should review all installations of the Threat Response product and verify whether the latest security update referenced in the Tanium advisory has been applied.

Risk and Exploitability

The CVSS score of 6.3 denotes a medium severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in CISA's KEV catalog. The attack vector is inferred to be local or domain‑bound, requiring authenticated access to the Threat Response interface or API, and the lack of proof of exploitation reduces immediate urgency.

Generated by OpenCVE AI on September 18, 2026 at 02:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the Tanium Threat Response update referenced in the Tanium advisory at https://security.tanium.com/TAN-2026-048.
  • Enforce least‑privilege role‑based access controls, ensuring users have only the permissions required for their tasks.
  • Monitor and audit Threat Response access logs for unauthorized or anomalous activity.

Generated by OpenCVE AI on September 18, 2026 at 02:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 18 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Tanium
Tanium threat Response
Vendors & Products Tanium
Tanium threat Response

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Wed, 16 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description Tanium addressed an improper access controls vulnerability in Threat Response.
Title Tanium addressed an improper access controls vulnerability in Threat Response.
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N'}


Subscriptions

Tanium Threat Response
cve-icon MITRE

Status: PUBLISHED

Assigner: Tanium

Published:

Updated: 2026-09-17T16:09:56.333Z

Reserved: 2026-09-08T20:39:21.860Z

Link: CVE-2026-87113

cve-icon Vulnrichment

Updated: 2026-09-17T16:09:48.663Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T20:17:38.090

Modified: 2026-09-18T19:19:49.643

Link: CVE-2026-87113

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T02:30:06Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key