CVE-2025-15318 PUBLISHED

Tanium addressed an arbitrary file deletion vulnerability in End-User Notifications Endpoint Tools.

Assigner: Tanium
Reserved: 29.12.2025 Published: 09.02.2026 Updated: 09.02.2026

Tanium addressed an arbitrary file deletion vulnerability in End-User Notifications Endpoint Tools.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS Score: 5.1

Product Status

Vendor Tanium
Product End-User Notifications Endpoint Tools
Versions
  • affected from 1.18.0 to 1.18.10079 (excl.)
  • affected from 10.0.0 to 10.0.14 (excl.)
  • affected from 10.1.0 to 10.1.20 (excl.)

References

Problem Types

  • Improper Link Resolution Before File Access ('Link Following') CWE