Junglewise Threat Intelligence

CVE-2026-87076: Tanium Discover information disclosure

CVE-2026-87076 · Severity: medium · CVSS 6.5 · Published 2026-09-16

Executive brief

Tanium Discover is an IT asset management and discovery tool used by enterprises to track and manage infrastructure. An authenticated user with specific asset discovery permissions could read sensitive data they should not be able to access, potentially exposing confidential asset information to unauthorized parties within an organization.

Technical details

This is an information disclosure vulnerability in Tanium Discover that allows authenticated users with the "Discover Asset Read" permission to access data beyond their authorization scope. The vulnerability requires authentication and the presence of specific permissions (AC:L indicates low attack complexity), but no user interaction is needed. An attacker with valid credentials and Asset Read permissions can gain unauthorized read-only access to restricted asset data. Patches are available across all affected release tracks: v4.10.190 and later (2025H1), v4.15.198 and later (2025H2), and v4.19.114 and later (2026H1).

Affected products

  • Tanium Discover prior to v4.10.190 (2025H1), v4.15.198 (2025H2), and v4.19.114 (2026H1)

Timeline

  • 2026-09-16: disclosed

References