CVE-2026-11925 Details
Description
Tanium addressed a User Interface (UI) Misrepresentation of Critical Information vulnerability in Tanium Server.
A vulnerability allowing for user interface misrepresentation of critical information has been identified in Tanium Server. This issue affects Tanium Server versions prior to Update MR21 in the 2025H1 release, prior to Update MR11 in the 2025H2 release, and prior to Update MR3 in the 2026H1 release. The vulnerability could allow an authenticated user with 'User Write' permission to conceal other users from the 'Users' management interface.
Users can upgrade to Tanium Server v7.7.3.8298 or later for the 2025H1 release, v7.8.2.1198 or later for the 2025H2 release, and v7.8.4.1327 or later for the 2026H1 release.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.tanium.com/TAN-2026-017 | Tanium | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-451 | User Interface (UI) Misrepresentation of Critical Information | Tanium |
Affected Products
| Product | Versions |
|---|---|
| tanium server | >= 7.7.3.0, < 7.7.3.8298 >= 7.8.2.0, < 7.8.2.1198 >= 7.8.4.0, < 7.8.4.1327 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 18, 2026 | Initial Analysis | [email protected] |
| Jul 22, 2026 | CVE Modified | CISA-ADP |
| Jul 21, 2026 | New CVE Received | Tanium |