Junglewise Threat Intelligence

CVE-2026-87032: Tanium Server information disclosure in data access control

CVE-2026-87032 · Severity: medium · CVSS 4.3 · Published 2026-09-09

Vendors: Tanium.

Executive brief

Tanium Server, an enterprise endpoint management and visibility platform, contains an information disclosure vulnerability that could allow authenticated users to read sensitive data they should not have access to. An attacker with valid credentials but no specific permissions could exploit this flaw to gain unauthorized read-only access to restricted information, potentially compromising confidentiality of sensitive operational or customer data.

Technical details

This is an information disclosure vulnerability (CWE-200) resulting from improper access control checks in Tanium Server's data access mechanisms. The vulnerability requires an authenticated user account but no special permissions to exploit. The attack vector is network-accessible and does not require user interaction. An authenticated attacker can bypass permission checks to read data they are not authorized to access. The vulnerability has been patched in: 2025H1 Release Update 21 (v7.7.3.8298) and later, 2025H2 Release Update 11 (v7.8.2.1198) and later, and 2026H1 Release Update 3 (v7.8.4.1327) and later.

Affected products

  • Tanium Server 2025H1 prior to v7.7.3.8298, 2025H2 prior to v7.8.2.1198, 2026H1 prior to v7.8.4.1327

Timeline

  • 2026-09-09: disclosed

References