Junglewise Threat Intelligence

CVE-2026-86865: Tanium Asset SQL injection

CVE-2026-86865 · Severity: high · CVSS 7.2 · Published 2026-09-16

Executive brief

Tanium Asset is a service that manages IT asset inventory and configuration across enterprise environments. A SQL injection vulnerability allows authenticated users with asset configuration permissions to manipulate database queries, potentially exposing sensitive asset data or modifying asset records, which could compromise IT governance and compliance reporting.

Technical details

A SQL injection vulnerability exists in Tanium Asset that allows an authenticated user with Asset Configuration Write permissions to inject arbitrary SQL commands into queries executed by the Asset service. The vulnerability is network-accessible (AV:N) with high complexity requirements (authenticated, high privileges required), but once exploited grants the attacker ability to read (C:H), modify (I:H), and potentially disrupt (A:H) asset database contents. The attack requires authentication and specific IAM permissions, limiting the attack surface. Patches are available: Asset v1.33.326 or later (2025H1), v1.36.174 or later (2025H2), and v1.39.153 or later (2026H1).

Affected products

  • Tanium Asset 2025H1 prior to Update 25 (v1.33.326), 2025H2 prior to Update 15 (v1.36.174), 2026H1 prior to Update 8 (v1.39.153)

Timeline

  • 2026-09-16: disclosed

References

Related threats