CVE-2026-87032
Awaiting Analysis Awaiting Analysis - Queue

Information Disclosure Vulnerability in Tanium Server

Vulnerability report for CVE-2026-87032, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: Tanium

Description

Tanium addressed an information disclosure vulnerability in Tanium Server.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
tanium tanium_server to 7.7.3.8298 (exc)
tanium tanium_server to 7.8.2.1198 (exc)
tanium tanium_server to 7.8.4.1327 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an information disclosure vulnerability in Tanium Server. It allows an authenticated user with no permissions to gain read-only access to data they should not be able to see. The vulnerability is rated Medium severity with a CVSS score of 4.3.

Detection Guidance

To detect this vulnerability, check the Tanium Server version against the affected releases. Use commands like 'tanium-server --version' or inspect the server logs for version details. Compare the output against the fixed versions: Update 21 (v7.7.3.8298) for 2025H1, Update 11 (v7.8.2.1198) for 2025H2, or Update 3 (v7.8.4.1327) for 2026H1.

Impact Analysis

An attacker with authenticated access could view sensitive data they are not authorized to see. This could lead to unauthorized data exposure, potential privacy breaches, or compliance violations depending on the data accessed.

Compliance Impact

This vulnerability could result in unauthorized access to personal or sensitive data, which may violate GDPR, HIPAA, or other privacy regulations. Organizations using affected Tanium Server versions may face compliance risks and potential penalties.

Mitigation Strategies

Update Tanium Server to the latest version: Update 21 (v7.7.3.8298) or later for 2025H1, Update 11 (v7.8.2.1198) or later for 2025H2, or Update 3 (v7.8.4.1327) or later for 2026H1. No other mitigations are provided.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87032. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart