Skip to content

TAN-2026-041

Tanium addressed an improper access controls vulnerability in Comply.

Severity: High

Base Score: 8.1

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Impact

This vulnerability could allow an authenticated Tanium user with the comply report write permission to delete assessments from the Comply database.

Products Affected

2025H1 Release:

  • Comply prior to Update 24 (v2.32 to v2.32.252)

2025H2 Release:

  • Comply prior to Update 14 (v2.35 to v2.35.306)

2026H1 Release:

  • Comply prior to Update 7 (v2.37 to v2.37.308)

Available Updates

2025H1 Release:

  • Update 24 (Comply v2.32.252) and later

2025H2 Release:

  • Update 14 (Comply v2.35.306) and later

2026H1 Release:

  • Update 7 (Comply v2.37.308) and later

Workaround and Mitigations

None.

Acknowledgements

None.