CVE-2026-11391

Summary

Tanium addressed a SQL injection vulnerability in Patch.

Affected Software

VendorProductVersion RangeStatus
TaniumPatch3.24.0 < 3.24.235affected
TaniumPatch3.28.0 < 3.28.232affected
TaniumPatch3.32.0 < 3.32.258affected

Weaknesses

  • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References