CVE-2025-15341 Details
Description
Tanium addressed an incorrect default permissions vulnerability in Benchmark.
A vulnerability allowing incorrect default permissions has been identified in Tanium's Benchmark, Comply, Discover, Partner Integration, Patch, and Performance products. This vulnerability affects several versions prior to specific update releases, allowing authenticated users with certain service account permissions to read and write all platform content.
Users can update to the latest versions of the affected products to address this vulnerability. Specific update versions can be found in the Tanium Security Advisory TAN-2025-029.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.tanium.com/TAN-2025-029 | Tanium | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-276 | Incorrect Default Permissions | Tanium |
Affected Products
| Product | Versions |
|---|---|
| tanium benchmark | >= 2.7.0, < 2.7.98 >= 2.9.0, < 2.9.188 >= 2.12.0, < 2.12.82 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Tanium |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 10, 2026 | Initial Analysis | [email protected] |
| Feb 5, 2026 | New CVE Received | Tanium |