CVE-2026-2435: ASSET-7706
Published Feb 19, 2026
·Updated
Tanium addressed a SQL injection vulnerability in Asset.
Affected Software
4 affected components
Tanium Asset
Tanium Asset>=1.32<1.32.179
Tanium Asset>=1.33<1.33.269
Tanium Asset>=1.36<1.36.108
Event History
Feb 19, 2026
CVE Published
via MITRE·11:09 PM
Data Sourced
via MITRE·11:09 PM
DescriptionSeverityWeakness
Feb 20, 2026
Data Sourced
via NVD·12:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-2435?
The severity of CVE-2026-2435 is rated as critical due to the potential for unauthorized data access.
2
How do I fix CVE-2026-2435?
To fix CVE-2026-2435, upgrade to the latest version of Tanium Asset that addresses the SQL injection vulnerability.
3
What impact does CVE-2026-2435 have on Tanium Asset?
CVE-2026-2435 allows attackers to execute arbitrary SQL queries through input fields, potentially compromising sensitive data.
4
Is CVE-2026-2435 a common vulnerability in Tanium Asset?
While SQL injection vulnerabilities are common, CVE-2026-2435 is specific to a version of Tanium Asset and should be addressed promptly.
5
When was CVE-2026-2435 reported?
CVE-2026-2435 was reported in 2026 and highlights a significant security issue in Tanium's Asset module.