Back to overview

CVE-2026-12139

MEDIUM
4.4
CVSS 3.1
Description
Tanium addressed an information disclosure vulnerability in Connect.

Metadata

CVE ID
CVE-2026-12139
State
PUBLISHED
Assigner
Tanium
Reserved
2026-06-12 17:05 UTC
Published
2026-07-21 20:25 UTC
Last updated
2026-07-22 19:40 UTC
Primary CWE
CWE-214
Invocation of Process Using Visible Sensitive Information
Vendor / Product
Tanium / Connect
Sources
cve.org  ·  NVD

Severity & Metrics

4.4 MEDIUM CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
Tanium Connect — 5.29.251 < 5.29.251, 5.37.156 < 5.37.156, 5.47.112 < 5.47.112
Weakness (CWE)
CWESourceDescription
CWE-214 cna Invocation of Process Using Visible Sensitive Information
CVSS scores (1)
ScoreSeverityVersionSourceVector
4.4 MEDIUM 3.1 cna CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
References (1)
Back to overview