Insecure File Permissions in Tanium Enforce Recovery Key Portal
CVE-2026-1344

6.5MEDIUM

Key Information:

Vendor

Tanium

Vendor
CVE Published:
17 February 2026

What is CVE-2026-1344?

The Tanium Enforce Recovery Key Portal is susceptible to an insecure file permissions vulnerability, which could potentially allow unauthorized access to sensitive files. This flaw arises from improper validation of file permissions, posing a risk to the integrity and confidentiality of the system. Users are encouraged to apply the latest security updates to mitigate risks associated with this vulnerability.

Affected Version(s)

Enforce Recovery Key Portal 1.0.0 < 1.62.5

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.