Refine your search

4 vulnerabilities found for Connect by Tanium

CVE-2026-12139 (GCVE-0-2026-12139)
Vulnerability from cvelistv5
Published
2026-07-21 20:25
Modified
2026-07-22 19:40
CWE
  • CWE-214 - Invocation of Process Using Visible Sensitive Information
Summary
Tanium addressed an information disclosure vulnerability in Connect.
Impacted products
Vendor Product Version
Tanium Connect Version: 5.29.251   < 5.29.251
Version: 5.37.156   < 5.37.156
Version: 5.47.112   < 5.47.112
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-12139",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-07-22T19:31:53.823237Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-07-22T19:40:47.897Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Connect",
          "vendor": "Tanium",
          "versions": [
            {
              "lessThan": "5.29.251",
              "status": "affected",
              "version": "5.29.251",
              "versionType": "custom"
            },
            {
              "lessThan": "5.37.156",
              "status": "affected",
              "version": "5.37.156",
              "versionType": "custom"
            },
            {
              "lessThan": "5.47.112",
              "status": "affected",
              "version": "5.47.112",
              "versionType": "custom"
            }
          ]
        }
      ],
      "dateAssigned": "2026-06-12T17:05:55.160Z",
      "datePublic": "2026-07-21T20:24:54.407Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "Tanium addressed an information disclosure vulnerability in Connect."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 4.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-214",
              "description": "Invocation of Process Using Visible Sensitive Information",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-07-21T20:25:14.577Z",
        "orgId": "3938794e-25f5-4123-a1ba-5cbd7f104512",
        "shortName": "Tanium"
      },
      "references": [
        {
          "name": "TAN-2026-018",
          "url": "https://security.tanium.com/TAN-2026-018"
        }
      ],
      "title": "Tanium addressed an information disclosure vulnerability in Connect."
    }
  },
  "cveMetadata": {
    "assignerOrgId": "3938794e-25f5-4123-a1ba-5cbd7f104512",
    "assignerShortName": "Tanium",
    "cveId": "CVE-2026-12139",
    "datePublished": "2026-07-21T20:25:14.577Z",
    "dateReserved": "2026-06-12T17:05:55.702Z",
    "dateUpdated": "2026-07-22T19:40:47.897Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-9208 (GCVE-0-2026-9208)
Vulnerability from cvelistv5
Published
2026-05-27 20:59
Modified
2026-05-28 13:22
CWE
  • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Summary
Tanium addressed an unauthorized code execution vulnerability in Connect.
Impacted products
Vendor Product Version
Tanium Connect Version: 5.26   < 5.26.191
Version: 5.29   < 5.29.237
Version: 5.37   < 5.37.140
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-9208",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-05-28T13:22:21.390236Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-05-28T13:22:32.052Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Connect",
          "vendor": "Tanium",
          "versions": [
            {
              "lessThan": "5.26.191",
              "status": "affected",
              "version": "5.26",
              "versionType": "custom"
            },
            {
              "lessThan": "5.29.237",
              "status": "affected",
              "version": "5.29",
              "versionType": "custom"
            },
            {
              "lessThan": "5.37.140",
              "status": "affected",
              "version": "5.37",
              "versionType": "custom"
            }
          ]
        }
      ],
      "dateAssigned": "2026-05-21T16:49:31.914Z",
      "datePublic": "2026-05-27T20:59:31.374Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "Tanium addressed an unauthorized code execution vulnerability in Connect."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-78",
              "description": "Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-05-27T20:59:43.199Z",
        "orgId": "3938794e-25f5-4123-a1ba-5cbd7f104512",
        "shortName": "Tanium"
      },
      "references": [
        {
          "name": "TAN-2026-015",
          "url": "https://security.tanium.com/TAN-2026-015"
        }
      ],
      "title": "Tanium addressed an unauthorized code execution vulnerability in Connect."
    }
  },
  "cveMetadata": {
    "assignerOrgId": "3938794e-25f5-4123-a1ba-5cbd7f104512",
    "assignerShortName": "Tanium",
    "cveId": "CVE-2026-9208",
    "datePublished": "2026-05-27T20:59:43.199Z",
    "dateReserved": "2026-05-21T16:49:32.433Z",
    "dateUpdated": "2026-05-28T13:22:32.052Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-9207 (GCVE-0-2026-9207)
Vulnerability from cvelistv5
Published
2026-05-27 01:19
Modified
2026-05-27 14:07
CWE
  • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Summary
Tanium addressed an unauthorized code execution vulnerability in Connect.
Impacted products
Vendor Product Version
Tanium Connect Version: 5.26   < 5.26.191
Version: 5.29   < 5.29.237
Version: 5.37   < 5.37.140
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-9207",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-05-27T13:50:58.138797Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-05-27T13:51:16.867Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Connect",
          "vendor": "Tanium",
          "versions": [
            {
              "lessThan": "5.26.191",
              "status": "affected",
              "version": "5.26",
              "versionType": "custom"
            },
            {
              "lessThan": "5.29.237",
              "status": "affected",
              "version": "5.29",
              "versionType": "custom"
            },
            {
              "lessThan": "5.37.140",
              "status": "affected",
              "version": "5.37",
              "versionType": "custom"
            }
          ]
        }
      ],
      "dateAssigned": "2026-05-21T16:46:15.094Z",
      "datePublic": "2026-05-27T01:19:08.632Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "Tanium addressed an unauthorized code execution vulnerability in Connect."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-78",
              "description": "Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-05-27T14:07:47.038Z",
        "orgId": "3938794e-25f5-4123-a1ba-5cbd7f104512",
        "shortName": "Tanium"
      },
      "references": [
        {
          "name": "TAN-2026-014",
          "url": "https://security.tanium.com/TAN-2026-014"
        }
      ],
      "title": "Tanium addressed an unauthorized code execution vulnerability in Connect."
    }
  },
  "cveMetadata": {
    "assignerOrgId": "3938794e-25f5-4123-a1ba-5cbd7f104512",
    "assignerShortName": "Tanium",
    "cveId": "CVE-2026-9207",
    "datePublished": "2026-05-27T01:19:26.555Z",
    "dateReserved": "2026-05-21T16:46:15.651Z",
    "dateUpdated": "2026-05-27T14:07:47.038Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2025-15331 (GCVE-0-2025-15331)
Vulnerability from cvelistv5
Published
2026-02-05 18:23
Modified
2026-02-06 19:14
CWE
Summary
Tanium addressed an uncontrolled resource consumption vulnerability in Connect.
Impacted products
Vendor Product Version
Tanium Connect Version: 5.22.0   < 5.22.100
Version: 5.26.0   < 5.26.87
    cpe:2.3:a:tanium:service_connect:5.22.99:*:*:*:*:*:*:*
    cpe:2.3:a:tanium:service_connect:5.26.86:*:*:*:*:*:*:*
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2025-15331",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-02-06T19:14:45.363886Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-02-06T19:14:52.895Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:tanium:service_connect:5.22.99:*:*:*:*:*:*:*",
            "cpe:2.3:a:tanium:service_connect:5.26.86:*:*:*:*:*:*:*"
          ],
          "product": "Connect",
          "vendor": "Tanium",
          "versions": [
            {
              "lessThan": "5.22.100",
              "status": "affected",
              "version": "5.22.0",
              "versionType": "custom"
            },
            {
              "lessThan": "5.26.87",
              "status": "affected",
              "version": "5.26.0",
              "versionType": "custom"
            }
          ]
        }
      ],
      "dateAssigned": "2025-12-29T23:13:31.267Z",
      "datePublic": "2025-04-16T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "Tanium addressed an uncontrolled resource consumption vulnerability in Connect."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-459",
              "description": "Incomplete Cleanup",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-02-05T18:23:51.939Z",
        "orgId": "3938794e-25f5-4123-a1ba-5cbd7f104512",
        "shortName": "Tanium"
      },
      "references": [
        {
          "name": "TAN-2025-015",
          "url": "https://security.tanium.com/TAN-2025-015"
        }
      ],
      "title": "Tanium addressed an uncontrolled resource consumption vulnerability in Connect."
    }
  },
  "cveMetadata": {
    "assignerOrgId": "3938794e-25f5-4123-a1ba-5cbd7f104512",
    "assignerShortName": "Tanium",
    "cveId": "CVE-2025-15331",
    "datePublished": "2026-02-05T18:23:51.939Z",
    "dateReserved": "2025-12-29T23:13:31.408Z",
    "dateUpdated": "2026-02-06T19:14:52.895Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}