Skip to content

TAN-2026-049

Tanium addressed a SQL injection vulnerability in Asset.

Severity: High

Base Score: 7.2

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Impact

This vulnerability could allow an authenticated Tanium user with the Asset Configuration Write permission to tamper with the SQL query executed by the Asset service.

Products Affected

2025H1 Release:

  • Asset prior to Update 25 (v1.33.326)

2025H2 Release:

  • Asset prior to Update 15 (v1.36.174)

2026H1 Release:

  • Asset prior to Update 8 (v1.39.153)

Available Updates

2025H1 Release:

  • Update 25 (Asset v1.33.326) and later

2025H2 Release:

  • Update 15 (Asset v1.36.174) and later

2026H1 Release:

  • Update 8 (Asset v1.39.153) and later

Workaround and Mitigations

None.

Acknowledgements

None.