Junglewise Threat Intelligence

CVE-2026-12139: Tanium Connect information disclosure in SMB destinations

CVE-2026-12139 · Severity: medium · CVSS 4.4 · Published 2026-07-21

Vendors: Tanium.

Executive brief

Tanium Connect is a module used to export data from the Tanium platform to external destinations like file shares or databases. A security vulnerability in this component could allow a high-privileged user on the server to discover sensitive login credentials used for SMB file shares. If exploited, this could lead to unauthorized access to corporate file storage systems where Tanium data is being sent.

Technical details

An information disclosure vulnerability exists in Tanium Connect due to the invocation of processes using visible sensitive information (CWE-214). Specifically, the application may expose SMB credentials used for Connect destinations to other processes or users on the local Tanium Module Server. Exploitation requires local access to the server and high privileges (PR:H). An attacker successfully exploiting this could retrieve plaintext credentials for SMB shares configured within the module. Tanium has released updates for the 2025H1, 2025H2, and 2026H1 release tracks to address this issue, and recommends rotating any potentially exposed credentials after patching.

Affected products

  • Tanium Connect prior to 5.29.251 (2025H1), prior to 5.37.156 (2025H2), prior to 5.47.112 (2026H1)

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Tanium advisory TAN-2026-018 published

References