CVE-2026-6416 is an uncontrolled resource consumption vulnerability affecting Tanium Interact that allows for denial of service conditions. The vulnerability has a low CVSS score of 2.7 and requires high-level privileges to exploit, with attacks deliverable over the network without user interaction. Based on current threat intelligence, there is no evidence of active exploitation, the vulnerability is not tracked in the Known Exploited Vulnerabilities catalog, and community attention remains minimal as indicated by its inactive status on public vulnerability hotlists. The extremely low EPSS probability score of 0.00036 further supports that real-world exploitation risk is negligible at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.2.0, < 3.2.202CPE match | cpe:2.3:a:tanium:interact:*:*:*:*:*:*:*:* | ||
>= 3.5.0, < 3.5.108CPE match | cpe:2.3:a:tanium:interact:*:*:*:*:*:*:*:* | ||
>= 3.8.0, < 3.8.47CPE match | cpe:2.3:a:tanium:interact:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.