Executive brief
Tanium Server, a platform used for managing and securing large enterprise networks, is affected by a vulnerability that can lead to a service outage. An attacker can send specially crafted messages to the server to exhaust its memory and file resources, causing the system to become unresponsive. This could disrupt IT operations and security monitoring across the organization until the server is restored.
Technical details
A denial of service vulnerability exists in Tanium Server due to a failure to release resources after their effective lifetime (CWE-772). By sending specifically crafted messages over the network, an attacker can trigger the exhaustion of file descriptors and system memory. Although the CVSS vector provided by the vendor (PR:L) suggests low privileges are required, the impact description mentions unauthenticated access may be possible. The vulnerability affects multiple release branches including 2024H2, 2025H1, and 2025H2. Patches have been released to address the resource management logic.
Affected products
- Tanium Tanium Server 7.6.4.2190 (2024H2 Update 25), 7.7.3.8274 (2025H1 Update 19), 7.8.2.1176 (2025H2 Update 9)
Timeline
- 2026-05-26: advisory: Tanium published security advisory TAN-2026-013
- 2026-05-27: disclosed: CVE-2026-9156 published to NVD