CVE-2026-11391
Received Received - Intake

SQL Injection Vulnerability in Tanium Patch

Vulnerability report for CVE-2026-11391, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-28

Last updated on: 2026-07-28

Assigner: Tanium

Description

Tanium addressed a SQL injection vulnerability in Patch.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-28
Last Modified
2026-07-28
Generated
2026-07-29
AI Q&A
2026-07-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
tanium patch to 3.24.235 (exc)
tanium patch to 3.28.232 (exc)
tanium patch to 3.32.258 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a SQL injection vulnerability in Tanium Patch. An authenticated user with specific permissions could manipulate SQL queries executed by the Patch service, potentially leading to unauthorized data access or modification.

Detection Guidance

Detection involves checking Patch service versions and monitoring for unusual SQL query patterns. Verify installed versions against affected releases (pre-Update 22 for 2025H1, pre-Update 12 for 2025H2, pre-Update 4 for 2026H1). Inspect logs for suspicious SQL queries or tampering attempts by users with 'Patch MDM Enforcement Write' permissions.

Impact Analysis

If exploited, this vulnerability could allow an attacker with Patch MDM Enforcement Write permission to tamper with SQL queries, potentially accessing or altering sensitive data managed by the Patch service.

Compliance Impact

The SQL injection vulnerability in Tanium Patch could allow unauthorized data access or modification, potentially violating GDPR (data protection) and HIPAA (health data security) requirements. Unauthorized SQL query tampering may lead to exposure or alteration of sensitive data, impacting compliance with these regulations.

Mitigation Strategies

Update Tanium Patch to versions at or above Update 22 (v3.24.235) for 2025H1, Update 12 (v3.28.232) for 2025H2, or Update 4 (v3.32.258) for 2026H1. Ensure only authorized users with Patch MDM Enforcement Write permission are granted access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-11391. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart