Skip to content

TAN-2026-046

Tanium addressed a SQL injection vulnerability in Asset.

Severity: High

Base Score: 7.2

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Impact

This vulnerability could allow an authenticated Tanium user with the Configuration Write permission to gain read and write access to data they should not have access to.

Products Affected

2025H1 Release:

  • Asset prior to Update 25 (v1.33.326)

2025H2 Release:

  • Asset prior to Update 15 (v1.36.174)

2026H1 Release:

  • Asset prior to Update 8 (v1.39.153)

Available Updates

2025H1 Release:

  • Update 25 (Asset v1.33.326) and later

2025H2 Release:

  • Update 15 (Asset v1.36.174) and later

2026H1 Release:

  • Update 8 (Asset v1.39.153) and later

Workaround and Mitigations

None.

Acknowledgements

None.