CVE-2026-14505: Tanium addressed a path traversal vulnerability in Tanium Data Service.
Published Sep 9, 2026
·Updated
Tanium addressed a path traversal vulnerability in Tanium Data Service.
Affected Software
1 affected component
Tanium Tanium Data Service
Event History
Sep 9, 2026
CVE Published
via MITRE·02:06 AM
Data Sourced
via MITRE·02:06 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access would an attacker need to exploit this issue?
The CVSS vector indicates that exploitation requires high privileges (PR:H). It is remotely reachable (AV:N), does not require user interaction, and has high attack complexity (AC:H).
2
What could exploitation allow an attacker to do?
The vulnerability is a path traversal issue. The CVSS vector assigns high impacts to confidentiality, integrity, and availability, indicating a successful exploit could affect all three.
3
Is user interaction required for exploitation?
No. The CVSS vector specifies UI:N, so no separate user action is required once an attacker has the necessary access and can satisfy the high-complexity exploitation conditions.