Executive brief
Tanium Comply is a compliance reporting and management service used by enterprises to monitor regulatory adherence. An authenticated user with specific permissions could execute arbitrary code within the Comply service, potentially compromising data integrity and allowing lateral movement within the compliance infrastructure.
Technical details
The vulnerability is an unauthorized code execution flaw in Tanium Comply that allows authenticated users with Comply Report Content Write and Comply Report Write permissions to execute arbitrary code in the context of the Comply service. The vulnerability is exploitable over the network without user interaction, though it requires high-privilege authentication and specific role permissions to trigger. An attacker with these permissions could achieve code execution with full impact to confidentiality, integrity, and availability. Patches are available via product updates: v2.32.252 or later (2025H1), v2.35.306 or later (2025H2), and v2.37.308 or later (2026H1).
Affected products
- Tanium Comply 2.32 to 2.32.251, 2.35 to 2.35.305, 2.37 to 2.37.307
Timeline
- 2026-09-09: disclosed