CVE-2026-9207 Details
Description
Tanium addressed an unauthorized code execution vulnerability in Connect.
A vulnerability allowing unauthorized code execution has been identified in Tanium Connect. This issue affects Tanium Module Server installations on Windows, specifically in the Connect component. The vulnerability arises from insufficient authorization, enabling an authenticated user with Connect Write permission to execute arbitrary code within the context of the Connect service on the Tanium Module Server.
Users can update to Tanium Connect version 5.26.191 or later (for the 2024H2 release), version 5.29.237 or later (for the 2025H1 release), version 5.37.140 or later (for the 2025H2 release), or version 5.47.95 or later (for the 2026H1 release) to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.tanium.com/TAN-2026-014 | Tanium | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | Tanium |
Affected Products
| Product | Versions |
|---|---|
| tanium connect | >= 5.26.0, < 5.26.191 >= 5.29.0, < 5.29.237 >= 5.37.0, < 5.37.140 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | Tanium |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 28, 2026 | Initial Analysis | [email protected] |
| May 27, 2026 | New CVE Received | Tanium |