Executive brief
Tanium Server, a widely-used endpoint management and security platform, contains an improper access control vulnerability that allows authenticated users to crash or degrade the service. An attacker with valid credentials could launch a denial-of-service attack, temporarily disrupting the organization's ability to manage and monitor endpoints across the network.
Technical details
The vulnerability is an improper access control flaw in Tanium Server that allows an authenticated user to trigger a denial-of-service condition. The attack requires valid Tanium credentials (authentication) and network access to the Tanium Server, but no user interaction. An attacker can abuse this control weakness to cause availability impact, preventing legitimate users from accessing server functionality. The vulnerability is fixed in Tanium Server v7.7.3.8298 (2025H1 Release Update 21), v7.8.2.1198 (2025H2 Release Update 11), and v7.8.4.1327 (2026H1 Release Update 3) and later versions.
Affected products
- Tanium Server 2025H1: 7.7.3 to 7.7.3.8298; 2025H2: 7.8.2 to 7.8.2.1198; 2026H1: 7.8.4 to 7.8.4.1327
Timeline
- 2026-09-09: disclosed