CVE-2026-12139
Analyzed
Analyzed - Analysis Complete
Information Disclosure in Tanium Connect
Vulnerability report for CVE-2026-12139, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-07-21
Last updated on: 2026-08-18
Assigner: Tanium
Description
Description
Tanium addressed an information disclosure vulnerability in Connect.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| tanium | connect | From 5.29.0 (inc) to 5.29.251 (exc) |
| tanium | connect | From 5.37.0 (inc) to 5.37.156 (exc) |
| tanium | connect | From 5.47.0 (inc) to 5.47.112 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-214 | A process is invoked with sensitive command-line arguments, environment variables, or other elements that can be seen by other processes on the operating system. |