CVE-2026-1224
Uncontrolled Resource Consumption in Tanium Discover Causes Denial of Service
Publication date: 2026-01-26
Last updated on: 2026-03-09
Assigner: Tanium
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| tanium | discover | From 4.15 (inc) to 4.15.130 (exc) |
| tanium | discover | From 4.10.0 (inc) to 4.10.134 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-770 | The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
CVE-2026-1224 is an uncontrolled resource consumption vulnerability in the Tanium Discover module. It allows an authenticated user with Discover Locations Write permission to perform a denial of service (DoS) attack by exhausting the resources of the Tanium Module Server. [1]
How can this vulnerability impact me? :
This vulnerability can impact you by enabling a denial of service (DoS) attack against the Tanium Module Server, potentially causing service disruption due to resource exhaustion. This could affect availability of the Tanium Discover service. [1]
What immediate steps should I take to mitigate this vulnerability?
The immediate step to mitigate this vulnerability is to apply the available updates for Tanium Discover. Specifically, update to Update 20 (v4.10.134) or later for the 2024H2 release, Update 13 (v4.10.134) or later for the 2025H1 release, or Update 3 (v4.15.130) or later for the 2025H2 release. No other workarounds or mitigations are provided. [1]