Executive brief
Tanium Asset, a data management and inventory tool, contains a SQL injection vulnerability that could allow authenticated users with configuration write permissions to access or modify data beyond their authorized scope. An attacker with these elevated privileges could extract sensitive information or corrupt critical asset records, bypassing normal access controls.
Technical details
A SQL injection vulnerability exists in Tanium Asset's data access layer, allowing an authenticated attacker with the Configuration Write permission to craft malicious SQL queries. The vulnerability requires valid credentials and elevated permissions but does not require user interaction. Exploitation could enable an attacker to read, write, or modify data stored in the Asset database without restriction, circumventing role-based access controls. Patches are available across all active release branches (2025H1 Update 25, 2025H2 Update 15, and 2026H1 Update 8).
Affected products
- Tanium Asset 2025H1 prior to Update 25 (v1.33.326), 2025H2 prior to Update 15 (v1.36.174), 2026H1 prior to Update 8 (v1.39.153)
Timeline
- 2026-09-16: disclosed
- 2026-09-16: patched: Updates available for all affected release branches