TAN-2026-046
Tanium addressed a SQL injection vulnerability in Asset.
Severity: High
Base Score: 7.2
Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Impact
This vulnerability could allow an authenticated Tanium user with the Configuration Write permission to gain read and write access to data they should not have access to.
Products Affected
2025H1 Release:
- Asset prior to Update 25 (v1.33.326)
2025H2 Release:
- Asset prior to Update 15 (v1.36.174)
2026H1 Release:
- Asset prior to Update 8 (v1.39.153)
Available Updates
2025H1 Release:
- Update 25 (Asset v1.33.326) and later
2025H2 Release:
- Update 15 (Asset v1.36.174) and later
2026H1 Release:
- Update 8 (Asset v1.39.153) and later
Workaround and Mitigations
None.
Acknowledgements
None.