Skip to content

TAN-2026-030

Tanium addressed an improper access controls vulnerability in Comply.

Severity: High

Base Score: 7.1

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Impact

This vulnerability could allow an authenticated Tanium user with the Comply Report permission to gain read and write access to data they should not have access to.

Products Affected

2025H1 Release:

  • Comply prior to Update 24 (v2.32 to v2.32.252)

2025H2 Release:

  • Comply prior to Update 14 (v2.35 to v2.35.306)

2026H1 Release:

  • Comply prior to Update 7 (v2.37 to v2.37.308)

Available Updates

2025H1 Release:

  • Update 24 (Comply v2.32.252) and later

2025H2 Release:

  • Update 14 (Comply v2.35.306) and later

2026H1 Release:

  • Update 7 (Comply v2.37.308) and later

Workaround and Mitigations

None.

Acknowledgements

None.