CVE-2026-9208 Details
Description
Tanium addressed an unauthorized code execution vulnerability in Connect.
A vulnerability allowing unauthorized code execution has been identified in Tanium Connect. This issue affects users with the Connect Write permission, who could execute unauthorized code in the context of the Connect service on the Tanium Module Server. The vulnerability is present in Tanium Connect versions prior to Update 25 (v5.26.191) in the 2024H2 Release, prior to Update 19 (v5.29.237) in the 2025H1 Release, prior to Update 9 (v5.37.140) in the 2025H2 Release, and prior to Update 0 (v5.47.95) in the 2026H1 Release.
Users can update to Tanium Connect v5.26.191 or later (for 2024H2 Release), v5.29.237 or later (for 2025H1 Release), v5.37.140 or later (for 2025H2 Release), or v5.47.95 or later (for 2026H1 Release).
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.tanium.com/TAN-2026-015 | Tanium | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | Tanium |
Affected Products
| Product | Versions |
|---|---|
| tanium connect | >= 5.26.0, < 5.26.191 >= 5.29.0, < 5.29.237 >= 5.37.0, < 5.37.140 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Tanium |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 2, 2026 | Initial Analysis | [email protected] |
| May 27, 2026 | New CVE Received | Tanium |