Junglewise Threat Intelligence

CVE-2026-87105: Tanium Threat Response SQL injection

CVE-2026-87105 · Severity: high · CVSS 8.8 · Published 2026-09-16

Executive brief

Tanium Threat Response, a security endpoint investigation service, is affected by a SQL injection vulnerability that allows authenticated attackers with client access to manipulate database queries. An exploit could enable unauthorized data tampering or exfiltration of sensitive threat intelligence data, potentially compromising an organization's security incident response capabilities.

Technical details

A SQL injection vulnerability in Tanium Threat Response allows an authenticated attacker with access to a system running the Tanium Client to tamper with SQL queries executed by the Threat Response service. The vulnerability requires authentication and local or network access to the Tanium Client. Successful exploitation enables reading, modifying, or deleting data from the underlying database, compromising both confidentiality and integrity. Patches are available across all affected releases: 2025H1 (Update 25 / v4.9.447+), 2025H2 (Update 15 / v4.12.317+), and 2026H1 (Update 8 / v4.17.289+).

Affected products

  • Tanium Threat Response 2025H1 prior to Update 25 (v4.9.447), 2025H2 prior to Update 15 (v4.12.317), 2026H1 prior to Update 8 (v4.17.289)

Timeline

  • 2026-09-16: disclosed

References

Related threats