Junglewise Threat Intelligence

CVE-2026-9207: Tanium Connect OS command injection in Module Server

CVE-2026-9207 · Severity: high · CVSS 8.8 · Published 2026-05-27

Vendors: Tanium.

Executive brief

Tanium Connect is a service used to integrate Tanium data with external systems like SIEMs or databases. A security flaw in this component allows an authorized user to run unauthorized commands on the underlying server. This could lead to a full system compromise, data theft, or disruption of the Tanium management environment, specifically for customers running the Tanium Module Server on Windows.

Technical details

An OS command injection vulnerability (CWE-78) exists in Tanium Connect when running on the Tanium Module Server on Windows. The flaw allows an authenticated attacker with 'Connect Write' permissions to execute unauthorized code in the context of the Connect service. The vulnerability stems from improper neutralization of special elements used in OS commands. Successful exploitation grants the attacker high-impact access to confidentiality, integrity, and availability of the host system. Patches are available across multiple release branches (2024H2, 2025H1, 2025H2, and 2026H1).

Affected products

  • Tanium Connect (2024H2 Release) prior to Update 25 (v5.26.191)
  • Tanium Connect (2025H1 Release) prior to Update 19 (v5.29.237)
  • Tanium Connect (2025H2 Release) prior to Update 9 (v5.37.140)

Timeline

  • 2026-05-26: disclosed: Initial disclosure by Tanium and NVD publication.
  • 2026-05-26: patched: Updates released for multiple Connect versions.

References