Executive brief
Tanium Enforce, a policy and compliance enforcement platform, contains a server-side request forgery vulnerability that allows authenticated users with enforce policy write permissions to read unauthorized data. This could enable insiders or compromised accounts to exfiltrate sensitive information despite not having explicit read access permissions.
Technical details
The vulnerability is a server-side request forgery (SSRF) in Tanium Enforce that can be exploited by authenticated users holding the enforce policy write permission. The flaw allows an attacker to make the Enforce server initiate requests to internal systems or endpoints, potentially reading data the attacker should not have access to. No user interaction is required beyond authentication, and the attack vector is over the network. The impact is confidentiality (high), with no impact on integrity or availability. Patches are available: Enforce v2.9.718+ (2025H1), v2.10.760+ (2025H2), and v3.0.346+ (2026H1).
Affected products
- Tanium Enforce 2.9 to 2.9.718 (2025H1), 2.10 to 2.10.760 (2025H2), 3.0 to 3.0.346 (2026H1)
Timeline
- 2026-09-09: disclosed
- 2026-09-09: patched: Updates available for all affected releases