ZeroHour

CVE-2026-87088

large

Local Command Injection in Tanium Enforce

CVSS 3.1
7.0 high
EPSS
<1%p2
Published
()
Modified
AI analysis

Tanium has patched an unauthorized code execution vulnerability in its Enforce product, classified as OS command injection (CWE-78). The CVSS 3.1 vector (AV:L/AC:H/PR:N/UI:R) indicates a local, high-complexity attack with no privileges required but user interaction needed, suggesting the flaw triggers when a local user initiates or approves an action whose input reaches an executed command. Successful exploitation results in code execution on the endpoint with high impact on confidentiality, integrity, and availability, likely with the elevated privileges under which the Tanium client runs. Only organizations running Tanium Enforce are affected; the available data does not specify which Enforce versions are vulnerable or which release contains the fix. There is no known public proof of concept, the issue is not in CISA's KEV, and EPSS assigns only a 0.1% probability of exploitation in the next 30 days, so no exploitation is currently observed.

What to do: Upgrade Tanium Enforce to the patched release per Tanium's advisory (fixed version not stated in this record; check the Tanium support portal for version details). Because exploitation requires local access and user interaction, prioritize patching endpoints where untrusted or unprivileged users can log in or run untrusted code. No in-the-wild exploitation or public PoC is known, so routine patch cycles are acceptable, and no mitigations are documented in the available data.

Affected
Tanium Enforce
Estimated exposure
largehundreds of thousands of enterprise endpoints (a subset of Tanium's multi-million-endpoint installed base); exact Enforce deployment counts unknown — Tanium is deployed across large enterprises and government agencies and publicly claims to manage millions of endpoints, of which Enforce customers represent a subset, so the affected population is plausibly in the hundreds of thousands of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Tanium addressed an unauthorized code execution vulnerability in Enforce.

Weakness
CWE-78
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.