Executive brief
Tanium has addressed a security flaw in its Connect module, which is used to integrate Tanium data with external SIEMs and databases. An authorized user with specific permissions could exploit this vulnerability to run unauthorized commands on the server hosting the Connect service. This could lead to a full system compromise, unauthorized data access, or disruption of data integration workflows.
Technical details
An OS command injection vulnerability (CWE-78) exists in Tanium Connect due to improper neutralization of special elements. An attacker must be authenticated and possess 'Connect Write' permissions to exploit this flaw. By sending a specially crafted request to the Connect service on the Tanium Module Server, the attacker can execute unauthorized code in the context of the service. The vulnerability affects multiple release branches (2024H2, 2025H1, 2025H2) and has been patched in Connect versions 5.26.191, 5.29.237, 5.37.140, and 5.47.95 respectively.
Affected products
- Tanium Connect 2024H2 Release prior to v5.26.191; 2025H1 Release prior to v5.29.237; 2025H2 Release prior to v5.37.140
Timeline
- 2026-05-27: disclosed: Initial publication of CVE-2026-9208 and TAN-2026-015
- 2026-05-27: patched: Updates released for affected versions