Executive brief
Tanium Threat Response, a security monitoring and threat detection platform, contains an improper access control vulnerability that allows authenticated users with alert management privileges to create or modify security alerts beyond their intended scope. An attacker with basic user credentials could circumvent role-based access controls to manipulate alerts, potentially hiding threats or creating false alerts that disrupt security operations.
Technical details
This is an improper access control vulnerability (CWE-284) in Tanium Threat Response's alert management functionality. The vulnerability allows an authenticated user with the "Threat Response Alerts Write" permission to access and modify alerts that should be restricted based on role-based access controls. The attack requires network access and valid authentication credentials, but no additional user interaction is needed. An attacker can exploit this to create unauthorized alerts or modify existing ones, potentially masking security incidents or triggering false alarms. Patches are available across all affected releases (2025H1 Update 25, 2025H2 Update 15, and 2026H1 Update 8).
Affected products
- Tanium Threat Response 2025H1 prior to Update 25 (v4.9.449), 2025H2 prior to Update 15 (v4.12.319), 2026H1 prior to Update 8 (v4.17.291)
Timeline
- 2026-09-16: disclosed