TAN-2026-040
Tanium addressed an unauthorized code execution vulnerability in Comply.
Severity: High
Base Score: 7.2
Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Impact
This vulnerability could allow an authenticated Tanium user with the Comply Report Content Write and Comply Report Write permissions to execute unauthorized code in the context of the Comply service.
Products Affected
2025H1 Release:
- Comply prior to Update 24 (v2.32 to v2.32.252)
2025H2 Release:
- Comply prior to Update 14 (v2.35 to v2.35.306)
2026H1 Release:
- Comply prior to Update 7 (v2.37 to v2.37.308)
Available Updates
2025H1 Release:
- Update 24 (Comply v2.32.252) and later
2025H2 Release:
- Update 14 (Comply v2.35.306) and later
2026H1 Release:
- Update 7 (Comply v2.37.308) and later
Workaround and Mitigations
None.
Acknowledgements
None.