CVE-2026-86865
8.8Tanium · Asset
Tanium Asset contains a SQL injection vulnerability that allows authenticated users to execute unauthorized database commands.
Executive summary
Tanium Asset is vulnerable to a SQL injection flaw that could allow an authenticated attacker to compromise the confidentiality, integrity, and availability of the underlying database.
Vulnerability
The application is susceptible to a SQL injection vulnerability, classified as CWE-89, which occurs due to improper neutralization of special elements in SQL commands. The CVSS vector indicates that a low-privileged authenticated user can trigger this flaw over the network without requiring user interaction.
Business impact
The exploitation of this vulnerability poses a significant risk to the organization as it grants an attacker the ability to execute arbitrary SQL commands. This may lead to unauthorized data exfiltration, modification of sensitive asset information, or potential disruption of service, causing significant operational and security impact. With a CVSS score of 8.8, this vulnerability is classified as high severity, reflecting the potential for full database compromise.
Remediation
Immediate Action: Upgrade Tanium Asset to version 1.33.326, 1.36.174, or 1.39.153 immediately to apply the vendor supplied security patches.
Proactive Monitoring: Review database audit logs for unusual query patterns, such as unexpected syntax or commands originating from non-standard user accounts, to detect potential exploitation attempts.
Compensating Controls: Ensure that the database service account operates with the principle of least privilege, restricting its ability to modify system tables or perform administrative actions that are not required for normal operation.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the severity of a SQL injection vulnerability and the potential for complete database compromise, organizations must prioritize the application of the vendor patches. Administrators should verify their current Tanium Asset version against the fixed release numbers provided and schedule maintenance windows to ensure these updates are deployed without delay.
More Tanium CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section