Junglewise Threat Intelligence

CVE-2026-6392: Tanium Threat Response information disclosure in Configs

CVE-2026-6392 · Severity: low · CVSS 2.7 · Published 2026-04-22

Executive brief

Tanium has addressed a security flaw in its Threat Response module, which is used by organizations to detect and respond to security incidents on endpoints. An authorized user with specific configuration-reading permissions could potentially view sensitive data they are not supposed to see. While the risk is low because it requires high-level access, it could lead to unauthorized internal information disclosure.

Technical details

An information disclosure vulnerability (CWE-200) exists in Tanium Threat Response due to insufficient access controls. An authenticated attacker with 'Threat Response Configs - Read' permissions can exploit this flaw over the network to gain read-only access to sensitive data beyond their intended scope. The vulnerability requires high privileges (PR:H) and has no impact on system integrity or availability. The issue is resolved in Threat Response versions 4.6.577 (Update 23), 4.9.379 (Update 17), and 4.12.251 (Update 7).

Affected products

  • Tanium Threat Response 4.6.0 to 4.6.577, 4.9.0 to 4.9.379

Timeline

  • 2026-04-21: disclosed
  • 2026-04-21: advisory
  • 2026-04-21: patched

References

Related threats