Skip to content

TAN-2026-019

Tanium addressed a SQL injection vulnerability in Patch.

Severity: Medium

Base Score: 6.3

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Impact

This vulnerability could allow an authenticated Tanium user with the "Patch MDM Enforcement Write" permission to tamper with the SQL query executed by the Patch service.

Products Affected

2025H1 Release:

  • Patch prior to Update 22 (v3.24.235)

2025H2 Release:

  • Patch prior to Update 12 (v3.28.232)

2026H1 Release:

  • Patch prior to Update 4 (v3.32.258)

Available Updates

2025H1 Release:

  • Update 22 (Patch v3.24.235) and later

2025H2 Release:

  • Update 12 (Patch v3.28.232) and later

2026H1 Release:

  • Update 4 (Patch v3.32.258) and later

Workaround and Mitigations

None.

Acknowledgements

None.