CVE-2026-6392 is an information disclosure vulnerability identified in Tanium Threat Response that could allow unauthorized access to sensitive data. The vulnerability requires network access and high-level privileges to exploit, with a CVSS score of 2.7 indicating low severity. The attack has low complexity and no user interaction requirement, but impact is limited to confidentiality with no integrity or availability concerns. There is currently no evidence of active exploitation, with the vulnerability absent from the Known Exploited Vulnerabilities catalog and marked as inactive on threat tracking lists. Community attention remains minimal, as reflected in the low EPSS score of 0.00025, suggesting this vulnerability presents limited risk to most organizations at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.6.0, < 4.6.577CPE match | cpe:2.3:a:tanium:threat_response:*:*:*:*:*:*:*:* | ||
>= 4.9.0, < 4.9.379CPE match | cpe:2.3:a:tanium:threat_response:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.