Executive brief
Tanium Threat Response is an enterprise security tool used to detect and respond to threats across an organization's systems. An authenticated attacker with specific permissions could exploit this vulnerability to read sensitive data they are not authorized to access, potentially exposing confidential business or security information.
Technical details
The vulnerability is a server-side request forgery (SSRF) flaw in Tanium Threat Response that allows authenticated users with the Threat Response Live Response Destinations Write permission to read unauthorized data. The attack requires valid authentication and the specific permission set, limiting exposure to internal or privileged users. An attacker can leverage the SSRF to access internal resources or data by manipulating server requests, compromising confidentiality without affecting system availability or integrity. Patches are available for all affected release branches: 2025H1 (Update 25 or later), 2025H2 (Update 15 or later), and 2026H1 (Update 8 or later).
Affected products
- Tanium Threat Response 2025H1 prior to v4.9.454, 2025H2 prior to v4.12.324, 2026H1 prior to v4.17.292
Timeline
- 2026-09-16: disclosed