Description
Tanium addressed a server-side request forgery vulnerability in Threat Response.
Published: 2026-09-16
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery (SRF)
Action: Apply Patch
AI Analysis

Impact

A server‑side request forgery flaw exists in Tanium Threat Response that allows an attacker to cause the server to send arbitrary HTTP requests on its behalf. This could enable data leakage, credential theft, or the execution of unintended actions on other hosts. The weakness is identified as CWE‑918.

Affected Systems

The vulnerability affects the Tanium Threat Response product. No specific version information is provided, so any deployment of Tanium Threat Response that has not yet received the vendor’s fix is potentially vulnerable.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate-to‑high risk, while the EPSS score is listed as less than 1 percent, suggesting a low probability of exploitation at the time of this analysis. The vulnerability is not included in CISA’s KEV catalog. Attackers would need to send tailored requests to the Threat Response server, likely requiring valid authentication, to trigger malicious outbound connections. Although exploitation evidence is limited, the nature of SRF makes the risk rise if the server can reach sensitive internal or external resources.

Generated by OpenCVE AI on September 17, 2026 at 21:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the Tanium Threat Response patch that contains the fix for the SRF vulnerability.
  • If a patch cannot be applied immediately, restrict the Threat Response server’s outbound network access to essential services and trusted endpoints.
  • Apply network segmentation to isolate the Threat Response server from critical internal resources and enforce strict egress filtering.
  • Monitor the server’s outgoing traffic for abnormal destinations or data transfers and set alerts for suspicious patterns.

Generated by OpenCVE AI on September 17, 2026 at 21:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 18 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Tanium
Tanium threat Response
Vendors & Products Tanium
Tanium threat Response

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description Tanium addressed a server-side request forgery vulnerability in Threat Response.
Title Tanium addressed a server-side request forgery vulnerability in Threat Response.
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Tanium Threat Response
cve-icon MITRE

Status: PUBLISHED

Assigner: Tanium

Published:

Updated: 2026-09-17T14:59:58.942Z

Reserved: 2026-09-08T20:57:43.536Z

Link: CVE-2026-87116

cve-icon Vulnrichment

Updated: 2026-09-17T14:59:56.247Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T20:17:38.207

Modified: 2026-09-18T19:19:49.643

Link: CVE-2026-87116

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T01:30:16Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)