Executive brief
Tanium has addressed a security flaw in its Patch module, which is used by organizations to manage and deploy software updates across their computer networks. An authorized user with specific permissions could potentially manipulate database queries to access or modify data they should not be able to reach. This could lead to unauthorized data disclosure or disruption of the patching service.
Technical details
A SQL injection vulnerability (CWE-89) exists in the Tanium Patch service. The flaw allows an authenticated attacker with 'Patch MDM Enforcement Write' permissions to inject malicious SQL commands into queries executed by the service. This is reachable over the network without user interaction. Successful exploitation could allow the attacker to read, modify, or delete data within the Patch service database, impacting confidentiality, integrity, and availability. The issue is resolved in Patch versions 3.24.235, 3.28.232, and 3.32.258.
Affected products
- Tanium Patch 3.24.0 to 3.24.234, 3.28.0 to 3.28.231, 3.32.0 to 3.32.257
Timeline
- 2026-07-28: disclosed
- 2026-07-28: advisory