Executive brief
Tanium Comply, a compliance management tool, contains an access control vulnerability that allows authenticated users with report-writing permissions to modify network reports outside their assigned content areas. An attacker with valid credentials and appropriate permissions could alter compliance reports, potentially leading to incorrect or false compliance data and unauthorized modifications to organizational records.
Technical details
The vulnerability is an improper access control issue in Tanium Comply that fails to properly validate authorization boundaries when modifying network reports. An authenticated user possessing the "Comply Report Write" permission can modify any network report regardless of content set ownership, bypassing intended access restrictions. The attack requires valid Tanium credentials and the specific "Comply Report Write" permission. An attacker can achieve unauthorized modification of compliance data across the organization. Patches are available: Comply v2.32.252 and later (2025H1), v2.35.306 and later (2025H2), and v2.37.308 and later (2026H1).
Affected products
- Tanium Comply 2.32 to 2.32.252 (2025H1), 2.35 to 2.35.306 (2025H2), 2.37 to 2.37.308 (2026H1)
Timeline
- 2026-09-09: disclosed