Tanium Trends Log File Vulnerability Allowing Sensitive Data Exposure

Vulnerability

A vulnerability has been identified in the Tanium Trends module that allows for the unintentional insertion of sensitive information into log files. This issue affects Tanium Trends versions 3.10.0 prior to 3.10.20, 3.11.0 prior to 3.11.79, and could enable an attacker with access to these logs to read sensitive data such as session information and API tokens.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive data in Trends module logs, including session details and API tokens.

Remediation

Users can upgrade to Tanium Trends version 3.10.20 or later, or version 3.11.79 or later, depending on their current release. Tanium On-prem users who suspect unauthorized access to their Trends logs should rotate the credentials for the Trends service account, stop the Tanium Server service to invalidate existing sessions, and review Trends logs for any improperly logged API tokens. Tanium Cloud users should rotate all API tokens.

Added: Feb 20, 2026, 12:29 AM
Updated: Feb 20, 2026, 12:29 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
3.3
remediation
0.0
relevance
3.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.