CVE-2026-87105

8.8

Tanium · Threat Response

Tanium Threat Response contains a SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands.

Executive summary

A high-severity SQL injection vulnerability in Tanium Threat Response allows an authenticated attacker to compromise database integrity, confidentiality, and availability.

Vulnerability

The application is susceptible to an improper neutralization of special elements used in an SQL command (CWE-89). This vulnerability requires the attacker to have low-level privileges to interact with the database interface.

Business impact

Successful exploitation of this SQL injection vulnerability could lead to unauthorized access to sensitive data stored within the Tanium database, including potential modification or deletion of forensic information. With a CVSS score of 8.8, this flaw presents a significant risk to the integrity of security operations and may facilitate further lateral movement within the network if the database contains credentials or configuration data.

Remediation

Immediate Action: Upgrade Tanium Threat Response to version 4.9.447, 4.12.317, 4.17.289, or later, as specified in the vendor advisory.

Proactive Monitoring: Review database audit logs for anomalous query patterns, unexpected syntax errors, or unauthorized data export commands originating from service accounts.

Compensating Controls: Implement strict input validation at the application layer and utilize a Web Application Firewall (WAF) to detect and block common SQL injection patterns targeting the management interface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the critical role of Threat Response in security infrastructure, organizations must prioritize the application of the provided patches. Administrators should verify their current version against the affected releases immediately and schedule an update window to mitigate the risk of unauthorized database manipulation.

More Tanium CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources