CVE-2026-9156 Details
Description
Tanium addressed a denial of service vulnerability in Tanium Server.
A denial-of-service vulnerability has been identified in Tanium Server. This issue allows an unauthenticated attacker with network access to the server to send crafted messages that can exhaust the server's file descriptors and memory, potentially leading to service disruption.
Users can upgrade to Tanium Server v7.6.4.2190 (Update 25), v7.7.3.8274 (Update 19), v7.8.2.1176 (Update 9) or v7.8.4.1298 (Update 0) to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.tanium.com/TAN-2026-013 | Tanium | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-772 | Missing Release of Resource after Effective Lifetime | Tanium |
Affected Products
| Product | Versions |
|---|---|
| tanium server | >= 7.6.4.0, < 7.6.4.2190 >= 7.7.3.0, < 7.7.3.8274 >= 7.8.2.0, < 7.8.2.1176 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | Tanium |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 29, 2026 | Initial Analysis | [email protected] |
| May 27, 2026 | New CVE Received | Tanium |