Incorrect Default Permissions in Tanium Partner Integration Software
CVE-2025-15338

6.5MEDIUM

Key Information:

Vendor

Tanium

Vendor
CVE Published:
5 February 2026

What is CVE-2025-15338?

Tanium's Partner Integration software has been found to have an incorrect default permissions configuration. This vulnerability can expose sensitive functionalities, potentially allowing unauthorized access to certain features. Organizations using this software should assess their security posture and consider applying relevant patches or updates to mitigate the associated risks. For further details, refer to TAN-2025-029 available at Tanium's security site.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Partner Integration 1.0.0 < 1.0.224

Partner Integration 1.2.0 < 1.2.33

Partner Integration 1.3.0 < 1.3.40

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.