CVE-2025-15314 PUBLISHED

Tanium addressed an arbitrary file deletion vulnerability in end-user-cx.

Assigner: Tanium
Reserved: 29.12.2025 Published: 09.02.2026 Updated: 09.02.2026

Tanium addressed an arbitrary file deletion vulnerability in end-user-cx.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS Score: 5.5

Product Status

Vendor Tanium
Product end-user-cx
Versions
  • affected from 1.4.0 to 1.4.1175 (excl.)
  • affected from 1.6.0 to 1.6.926 (excl.)
  • affected from 1.8.0 to 1.8.21 (excl.)

References

Problem Types

  • Improper Link Resolution Before File Access ('Link Following') CWE