CVE-2026-1344 PUBLISHED

Insecure file permissions in Enforce Recovery Key Portal

Assigner: Tanium
Reserved: 22.01.2026 Published: 17.02.2026 Updated: 18.02.2026

Tanium addressed an insecure file permissions vulnerability in Enforce Recovery Key Portal.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CVSS Score: 6.5

Product Status

Vendor Tanium
Product Enforce Recovery Key Portal
Versions
  • affected from 1.0.0 to 1.62.5 (excl.)

References

Problem Types

  • Incorrect Permission Assignment for Critical Resource CWE