CVE-2026-2350 Details
Description
Tanium addressed an insertion of sensitive information into log file vulnerability in Interact and TDS.
A vulnerability allowing the insertion of sensitive information into log files has been identified in Tanium Interact and Tanium Data Service (TDS). This issue affects specific versions of Tanium Interact and TDS, where sensitive data such as session information and API tokens could be exposed in the logs.
Users of Tanium Interact should upgrade to version 3.2.196 or later if on the 2024H2 release, or version 3.5.102 or later if on the 2025H1 release. Tanium TDS users should upgrade to version 4.1.257 or later. Tanium On-prem users who suspect unauthorized access to their TDS logs should rotate the credentials for the TDS service account, stop the Tanium Server service to invalidate existing sessions, and review TDS logs for any API tokens that were improperly logged. Tanium Cloud users should rotate all API tokens.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.tanium.com/TAN-2026-008 | Tanium | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-532 | Insertion of Sensitive Information into Log File | Tanium |
Affected Products
| Product | Versions |
|---|---|
| tanium interact | >= 3.2.0, < 3.2.196 >= 3.5.0, < 3.5.102 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Tanium |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 27, 2026 | Initial Analysis | [email protected] |
| Feb 20, 2026 | New CVE Received | Tanium |