Skip to content

TAN-2026-040

Tanium addressed an unauthorized code execution vulnerability in Comply.

Severity: High

Base Score: 7.2

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Impact

This vulnerability could allow an authenticated Tanium user with the Comply Report Content Write and Comply Report Write permissions to execute unauthorized code in the context of the Comply service.

Products Affected

2025H1 Release:

  • Comply prior to Update 24 (v2.32 to v2.32.252)

2025H2 Release:

  • Comply prior to Update 14 (v2.35 to v2.35.306)

2026H1 Release:

  • Comply prior to Update 7 (v2.37 to v2.37.308)

Available Updates

2025H1 Release:

  • Update 24 (Comply v2.32.252) and later

2025H2 Release:

  • Update 14 (Comply v2.35.306) and later

2026H1 Release:

  • Update 7 (Comply v2.37.308) and later

Workaround and Mitigations

None.

Acknowledgements

None.