Tanium Partner Integration
cpe:2.3:a:tanium:tanium:*:*:*:*:*:*:*
- < 1.0.224
- < 1.2.33
- < 1.3.40
A vulnerability allowing incorrect default permissions has been identified in Tanium's Partner Integration component. This issue affects several versions prior to the 2025H1 release, specifically those before Update 5. The vulnerability could enable an authenticated Tanium user with certain service account permissions to read or write all platform content.
Exploitation of this vulnerability could allow an authenticated user with specific service account permissions to read and write all platform content, potentially leading to unauthorized data access or modification.
Users can update to Tanium Partner Integration version 1.3.40 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.