Executive brief
Tanium Threat Response, a security operations platform used to detect and respond to threats, contains an access control weakness that allows authenticated users with specific permissions to create or modify threat suppression rules. This could enable malicious insiders or compromised accounts to suppress legitimate security alerts, reducing the organization's ability to detect and respond to actual security incidents.
Technical details
The vulnerability is an improper access control issue in Tanium Threat Response that fails to properly validate permissions when users attempt to create or modify suppression rules. An authenticated user with the "Threat Response Intel Write" permission can exploit this to create or modify threat suppression rules beyond their intended authorization level. The attack requires network access and valid Tanium credentials with the specified permission; no additional user interaction is needed. Patches are available for all affected release branches: 2025H1 (Update 25 v4.9.454), 2025H2 (Update 15 v4.12.324), and 2026H1 (Update 8 v4.17.292).
Affected products
- Tanium Threat Response 2025H1 prior to v4.9.454, 2025H2 prior to v4.12.324, 2026H1 prior to v4.17.292
Timeline
- 2026-09-16: disclosed