Junglewise Threat Intelligence

CVE-2026-87088: Tanium Enforce local privilege escalation via malicious quarantine file

CVE-2026-87088 · Severity: high · CVSS 7 · Published 2026-09-09

Vendors: Tanium.

Executive brief

Tanium Enforce is an endpoint detection and response (EDR) solution used to protect corporate systems from threats. A vulnerability allows an attacker with local access to a system running the Tanium Client to escalate privileges to system level when a maliciously-named file in antivirus quarantine is processed during remediation actions. This could give attackers full control over protected systems.

Technical details

A local privilege escalation vulnerability exists in Tanium Enforce's remediation action processing, triggered when handling maliciously-named files already present in antivirus quarantine. The vulnerability requires local access to a system with Tanium Client installed and user interaction (remediation action execution), but allows an authenticated or unprivileged attacker to achieve high-integrity code execution with system privileges. The vulnerability affects Enforce versions 2.9.x through 2.9.718, 2.10.x through 2.10.760, and 3.0.x through 3.0.346. Patches are available: Update 24 (v2.9.718) for 2025H1, Update 14 (v2.10.760) for 2025H2, and Update 7 (v3.0.346) for 2026H1.

Affected products

  • Tanium Enforce 2.9 to 2.9.718 (2025H1), 2.10 to 2.10.760 (2025H2), 3.0 to 3.0.346 (2026H1)

Timeline

  • 2026-09-09: disclosed
  • 2026-09-09: patched: Patches available: v2.9.718 (2025H1 Update 24), v2.10.760 (2025H2 Update 14), v3.0.346 (2026H1 Update 7)

References

Related threats