CVE-2026-9208

8.8

Tanium · Connect

Tanium Connect is vulnerable to OS command injection, which could allow an authenticated attacker to execute unauthorized commands on the underlying system.

Executive summary

Tanium Connect contains an OS command injection vulnerability that could permit an authenticated attacker to execute arbitrary system-level code.

Vulnerability

This is an OS command injection vulnerability (CWE-78). The CVSS vector indicates that while the vulnerability is remotely exploitable (AV:N), it requires low privileges (PR:L), meaning the attacker must be authenticated to the Tanium platform.

Business impact

An OS command injection vulnerability poses a severe risk, as it allows attackers to bypass security controls and execute commands with the privileges of the Tanium Connect service. This could result in full system takeover, unauthorized data access, and the ability to manipulate the Tanium infrastructure itself. The CVSS score of 8.8 justifies an immediate response to secure the management platform.

Remediation

Immediate Action: Apply the vendor-provided security updates to reach versions 5.26.191, 5.29.237, or 5.37.140 as specified in the Tanium advisory TAN-2026-015.

Proactive Monitoring: Review audit logs for unusual command execution patterns or unauthorized modifications to Tanium Connect task configurations.

Compensating Controls: Ensure that access to the Tanium administrative console is strictly restricted to authorized personnel using Multi-Factor Authentication (MFA) to minimize the risk of unauthorized access.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical nature of the Tanium platform within enterprise environments, it is imperative to apply the provided patches immediately. Restricting access to the platform and ensuring all administrative users are authenticated via robust identity management is essential to prevent exploitation of this vulnerability.

More Tanium CVEs