Executive brief
Tanium Data Service is a component used to collect and manage operational data across enterprise infrastructure. A path traversal vulnerability allows authenticated users with specific administrative permissions to write arbitrary files to the underlying server, potentially compromising system integrity and enabling further attacks on the deployment.
Technical details
The vulnerability is a path traversal flaw in Tanium Data Service that allows authenticated users with the "Data Collection Pipeline Write Override" permission to bypass file write restrictions and place arbitrary files on the Tanium Module Server. The attack requires authentication and elevated permissions, but no user interaction is needed. An attacker with these credentials could write malicious files to arbitrary locations, potentially leading to code execution or system compromise. The vulnerability affects Tanium Data Service v4.2 through v4.2.345 in the 2026H1 release and is fixed in Update 4 (v4.2.345) and later.
Affected products
- Tanium Data Service 4.2 to 4.2.345 (2026H1 Release)
Timeline
- 2026-09-09: disclosed