Junglewise Threat Intelligence

CVE-2026-11925: Tanium Server UI misrepresentation in user management

CVE-2026-11925 · Severity: low · CVSS 2.7 · Published 2026-07-21

Vendors: Tanium.

Executive brief

Tanium Server, a platform used for endpoint management and security, contained a flaw where certain administrative users could hide other user accounts from the management interface. While this does not grant unauthorized access to data, it could allow a malicious insider to obscure the presence of other accounts from administrators, potentially complicating audits or user management. Tanium has released updates to ensure all user accounts are correctly represented in the management console.

Technical details

A User Interface (UI) Misrepresentation of Critical Information vulnerability (CWE-451) exists in Tanium Server. An authenticated attacker with 'User Write' permissions can exploit this flaw to hide other user accounts from the 'Users' management UI. The attack is carried out over the network and requires high privileges (PR:H) but no user interaction. This could be used to mask the existence of specific accounts from other administrators. The issue is resolved in Tanium Server versions 7.7.3.8298, 7.8.2.1198, and 7.8.4.1327.

Affected products

  • Tanium Tanium Server prior to 7.7.3.8298 (2025H1), prior to 7.8.2.1198 (2025H2), prior to 7.8.4.1327 (2026H1)

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats