Skip to content

TAN-2026-038

Tanium addressed an improper access controls vulnerability in Comply.

Severity: Medium

Base Score: 6.3

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Impact

This vulnerability could allow an authenticated Tanium user with the Comply Report Read, Comply Report Content Read, or Comply Report Write permission to gain read or write access to data they should not have access to.

Products Affected

2025H1 Release:

  • Comply prior to Update 24 (v2.32 to v2.32.252)

2025H2 Release:

  • Comply prior to Update 14 (v2.35 to v2.35.306)

2026H1 Release:

  • Comply prior to Update 7 (v2.37 to v2.37.308)

Available Updates

2025H1 Release:

  • Update 24 (Comply v2.32.252) and later

2025H2 Release:

  • Update 14 (Comply v2.35.306) and later

2026H1 Release:

  • Update 7 (Comply v2.37.308) and later

Workaround and Mitigations

None.

Acknowledgements

None.