Tanium Benchmark
cpe:2.3:a:tanium:tanium:*:*:*:*:*:*:*
- < 2.7.98
- < 2.24.159
- < 4.10.118
- < 1.0.224
- < 3.17.2300
- < 1.17.134
- < 2.9.188
- < 2.29.124
- < 1.2.33
- < 3.19.232
- < 1.21.141
- < 2.12.82
- < 2.32.155
- < 1.3.40
- < 3.24.137
- < 1.22.288
A vulnerability allowing incorrect default permissions has been identified in Tanium's Benchmark, Comply, Discover, Partner Integration, Patch, and Performance products. This vulnerability affects several versions prior to specific update releases, allowing authenticated users with certain service account permissions to read and write all platform content.
Exploitation of this vulnerability could enable an authenticated user with specific service account permissions to read and write all platform content, potentially leading to unauthorized data manipulation or access.
Users can update to the latest versions of the affected products to address this vulnerability. Specific update versions can be found in the Tanium Security Advisory TAN-2025-029.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.