Tanium Performance Incorrect Default Permissions Vulnerability Allowing Unauthorized Content Access

Vulnerability

An incorrect default permissions vulnerability has been identified in Tanium Performance, prior to Update 6 (v1.22.288). This vulnerability allows an authenticated Tanium user with specific service account permissions to read and write all platform content. The issue arises from improper default permission settings that could be exploited by users with certain roles.

Impact

Exploitation of this vulnerability could enable an authenticated user with the appropriate service account permissions to access and modify all platform content, potentially leading to unauthorized data manipulation or exposure.

Remediation

Users can update to Tanium Performance version 1.22.288 or later to address this vulnerability.

Added: Feb 5, 2026, 7:27 PM
Updated: Feb 5, 2026, 8:54 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
5.0
exploitability
4.4
remediation
7.7
relevance
2.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.