CVE-2026-86865

8.8

Tanium · Asset

Tanium Asset contains a SQL injection vulnerability that allows authenticated users to execute unauthorized database commands.

Executive summary

Tanium Asset is vulnerable to a SQL injection flaw that could allow an authenticated attacker to compromise the confidentiality, integrity, and availability of the underlying database.

Vulnerability

The application is susceptible to a SQL injection vulnerability, classified as CWE-89, which occurs due to improper neutralization of special elements in SQL commands. The CVSS vector indicates that a low-privileged authenticated user can trigger this flaw over the network without requiring user interaction.

Business impact

The exploitation of this vulnerability poses a significant risk to the organization as it grants an attacker the ability to execute arbitrary SQL commands. This may lead to unauthorized data exfiltration, modification of sensitive asset information, or potential disruption of service, causing significant operational and security impact. With a CVSS score of 8.8, this vulnerability is classified as high severity, reflecting the potential for full database compromise.

Remediation

Immediate Action: Upgrade Tanium Asset to version 1.33.326, 1.36.174, or 1.39.153 immediately to apply the vendor supplied security patches.

Proactive Monitoring: Review database audit logs for unusual query patterns, such as unexpected syntax or commands originating from non-standard user accounts, to detect potential exploitation attempts.

Compensating Controls: Ensure that the database service account operates with the principle of least privilege, restricting its ability to modify system tables or perform administrative actions that are not required for normal operation.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the severity of a SQL injection vulnerability and the potential for complete database compromise, organizations must prioritize the application of the vendor patches. Administrators should verify their current Tanium Asset version against the fixed release numbers provided and schedule maintenance windows to ensure these updates are deployed without delay.

More Tanium CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources