Executive brief
Tanium has addressed a security flaw in its Threat Response module, which is used by organizations to detect and respond to security incidents on endpoints. An authorized user with specific configuration-reading permissions could potentially view sensitive data they are not supposed to see. While the risk is low because it requires high-level access, it could lead to unauthorized internal information disclosure.
Technical details
An information disclosure vulnerability (CWE-200) exists in Tanium Threat Response due to insufficient access controls. An authenticated attacker with 'Threat Response Configs - Read' permissions can exploit this flaw over the network to gain read-only access to sensitive data beyond their intended scope. The vulnerability requires high privileges (PR:H) and has no impact on system integrity or availability. The issue is resolved in Threat Response versions 4.6.577 (Update 23), 4.9.379 (Update 17), and 4.12.251 (Update 7).
Affected products
- Tanium Threat Response 4.6.0 to 4.6.577, 4.9.0 to 4.9.379
Timeline
- 2026-04-21: disclosed
- 2026-04-21: advisory
- 2026-04-21: patched