TAN-2026-019
Tanium addressed a SQL injection vulnerability in Patch.
Severity: Medium
Base Score: 6.3
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Impact
This vulnerability could allow an authenticated Tanium user with the "Patch MDM Enforcement Write" permission to tamper with the SQL query executed by the Patch service.
Products Affected
2025H1 Release:
- Patch prior to Update 22 (v3.24.235)
2025H2 Release:
- Patch prior to Update 12 (v3.28.232)
2026H1 Release:
- Patch prior to Update 4 (v3.32.258)
Available Updates
2025H1 Release:
- Update 22 (Patch v3.24.235) and later
2025H2 Release:
- Update 12 (Patch v3.28.232) and later
2026H1 Release:
- Update 4 (Patch v3.32.258) and later
Workaround and Mitigations
None.
Acknowledgements
None.