ZeroHour

CVE-2026-87084

moderate

Server-Side Request Forgery (SSRF) in Tanium Enforce

CVSS 3.1
7.7 high
EPSS
<1%p10
Published
()
Modified
AI analysis

Tanium has addressed a server-side request forgery (SSRF, CWE-918) vulnerability in its Enforce product, in which the server can be induced to issue requests to attacker-chosen destinations. Per the CVSS vector, exploitation requires low-privileged (authenticated) access over the network and no user interaction, and the changed scope (S:C) indicates a forged request can cross a trust boundary to reach other internal systems or services. An attacker gains a high degree of confidentiality impact — typically the ability to probe or retrieve data from internal networks, cloud metadata endpoints, or otherwise inaccessible services — with no integrity or availability impact indicated. Any organization operating a Tanium Enforce deployment is affected, particularly where untrusted or low-trust users can authenticate to the product's interface or API. There is no known public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at a low 0.2%, so exploitation is not currently observed.

What to do: Update Tanium Enforce to the patched release identified in Tanium's advisory, since the affected/fixed version numbers are not included in this data. Limit which low-privileged users can authenticate to Enforce and review outbound network access from the Enforce server (e.g., egress rules and access to internal services or cloud metadata endpoints) to reduce SSRF blast radius. No public PoC or in-the-wild exploitation is known, so patching at the next normal maintenance window is a reasonable cadence for most defenders.

Affected
Tanium Enforce
Estimated exposure
moderatelikely on the order of 1,000–10,000 Enforce server deployments (exact counts not published) — Tanium is concentrated in large enterprise and public-sector environments (thousands of customer organizations), but Enforce is a specific server-side module not universally deployed, so the count of Enforce server installations is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Tanium addressed a server-side request forgery vulnerability in Enforce.

Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.