CVE-2026-87088
largeLocal Command Injection in Tanium Enforce
Tanium has patched an unauthorized code execution vulnerability in its Enforce product, classified as OS command injection (CWE-78). The CVSS 3.1 vector (AV:L/AC:H/PR:N/UI:R) indicates a local, high-complexity attack with no privileges required but user interaction needed, suggesting the flaw triggers when a local user initiates or approves an action whose input reaches an executed command. Successful exploitation results in code execution on the endpoint with high impact on confidentiality, integrity, and availability, likely with the elevated privileges under which the Tanium client runs. Only organizations running Tanium Enforce are affected; the available data does not specify which Enforce versions are vulnerable or which release contains the fix. There is no known public proof of concept, the issue is not in CISA's KEV, and EPSS assigns only a 0.1% probability of exploitation in the next 30 days, so no exploitation is currently observed.
What to do: Upgrade Tanium Enforce to the patched release per Tanium's advisory (fixed version not stated in this record; check the Tanium support portal for version details). Because exploitation requires local access and user interaction, prioritize patching endpoints where untrusted or unprivileged users can log in or run untrusted code. No in-the-wild exploitation or public PoC is known, so routine patch cycles are acceptable, and no mitigations are documented in the available data.
| Tanium Enforce | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Tanium addressed an unauthorized code execution vulnerability in Enforce.
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.