Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-87113

CVE-2026-87113: Tanium Threat Response Auth Bypass

CVE-2026-87113 is an authentication bypass vulnerability in Tanium Threat Response caused by improper access controls. Attackers can exploit this flaw to gain unauthorized access. This article covers technical details, affected versions, security impact, and recommended mitigation strategies.

Updated:

CVE-2026-87113 Overview

CVE-2026-87113 is an improper access controls vulnerability in Tanium Threat Response. Tanium addressed the issue in a security update published under advisory TAN-2026-048. The weakness is categorized as [CWE-639] Authorization Bypass Through User-Controlled Key, an Insecure Direct Object Reference (IDOR) class flaw.

An authenticated attacker with low privileges can reach the vulnerability over the network without user interaction. Successful exploitation can lead to limited impact on confidentiality, integrity, and availability of Threat Response data.

Critical Impact

An authenticated low-privileged user can bypass authorization checks in Tanium Threat Response and access or modify resources belonging to other users.

Affected Products

  • Tanium Threat Response

Discovery Timeline

  • 2026-09-16 - CVE-2026-87113 published to the National Vulnerability Database
  • 2026-09-16 - Last updated in NVD database
  • Vendor advisory - Published as Tanium Security Advisory TAN-2026-048

Technical Details for CVE-2026-87113

Vulnerability Analysis

The vulnerability affects Tanium Threat Response, a module used for endpoint detection and incident response across managed environments. The flaw is classified under [CWE-639], which describes authorization bypass conditions where a user-controlled key or identifier is used to reference resources without proper access checks.

An attacker with valid low-privileged credentials to the Tanium environment can craft requests that target resources they should not be permitted to view or modify. Because Threat Response handles sensitive investigation data, endpoint queries, and response actions, unauthorized access can expose forensic artifacts or allow tampering with response workflows.

Exploitation requires network access to the Threat Response interface and existing authentication. No user interaction is required, and the attack complexity is low.

Root Cause

The root cause is missing or insufficient authorization validation when Threat Response processes requests referencing object identifiers. The application trusts a user-supplied key to select the target resource without verifying that the caller has rights to that specific object. This is the classic pattern behind IDOR vulnerabilities.

Attack Vector

The attack vector is network-based. An authenticated attacker sends crafted requests to Threat Response API endpoints, substituting object identifiers to reach data belonging to other tenants, users, or investigations. See the Tanium Security Advisory TAN-2026-048 for vendor-supplied technical context.

No verified public proof-of-concept code is available for CVE-2026-87113 at the time of publication.

Detection Methods for CVE-2026-87113

Indicators of Compromise

  • Unexpected access patterns to Threat Response resources by low-privileged accounts.
  • API requests containing sequential or enumerated object identifiers referencing resources outside the caller's scope.
  • Audit log entries showing successful reads or modifications to investigations that the acting user should not own.

Detection Strategies

  • Review Tanium audit logs for authorization decisions that granted access to resources across role or tenant boundaries.
  • Baseline normal Threat Response API usage per role, then alert on deviations such as bulk identifier enumeration.
  • Correlate authentication events with resource access to identify accounts issuing anomalous cross-scope queries.

Monitoring Recommendations

  • Forward Tanium Threat Response audit and access logs to a centralized SIEM for retention and correlation.
  • Alert on repeated 200-status responses to endpoints that also produce 403 responses for the same session, suggesting probing.
  • Monitor for privilege changes and new low-privileged account creations that precede unusual Threat Response activity.

How to Mitigate CVE-2026-87113

Immediate Actions Required

  • Apply the fix described in Tanium Security Advisory TAN-2026-048 as soon as it is available in your maintenance window.
  • Inventory all Tanium Threat Response instances and confirm their current version against the advisory's fixed release.
  • Review recently created or modified low-privileged accounts with access to Threat Response and rotate credentials where suspicious activity is observed.

Patch Information

Tanium has addressed CVE-2026-87113 in Threat Response. Refer to Tanium Security Advisory TAN-2026-048 for the fixed version numbers and upgrade guidance. Customers should follow Tanium's standard upgrade process for the Threat Response module.

Workarounds

  • Restrict Threat Response console and API access to a minimum set of trusted operators until patching is complete.
  • Enforce least-privilege role assignments and remove Threat Response permissions from accounts that do not require them.
  • Place the Tanium management interface behind network segmentation and require VPN or bastion access to reduce exposure.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.