TAN-2026-049
Tanium addressed a SQL injection vulnerability in Asset.
Severity: High
Base Score: 7.2
Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Impact
This vulnerability could allow an authenticated Tanium user with the Asset Configuration Write permission to tamper with the SQL query executed by the Asset service.
Products Affected
2025H1 Release:
- Asset prior to Update 25 (v1.33.326)
2025H2 Release:
- Asset prior to Update 15 (v1.36.174)
2026H1 Release:
- Asset prior to Update 8 (v1.39.153)
Available Updates
2025H1 Release:
- Update 25 (Asset v1.33.326) and later
2025H2 Release:
- Update 15 (Asset v1.36.174) and later
2026H1 Release:
- Update 8 (Asset v1.39.153) and later
Workaround and Mitigations
None.
Acknowledgements
None.