Executive brief
Tanium Comply is a compliance management platform used by enterprises to track and manage regulatory requirements across their IT infrastructure. A vulnerability in Comply allows authenticated users with report-writing permissions to read data they should not have access to, risking exposure of sensitive compliance or configuration information.
Technical details
This is an information disclosure vulnerability (CWE-200) in Tanium Comply. The vulnerability requires authentication and the user must possess the "comply report write" permission to exploit it. An authenticated attacker can gain unintended read-only access to restricted data through the Comply API or interface. The vulnerability affects Tanium Comply versions prior to Update 7 (v2.37.308) in the 2026H1 release. The fix is available in Comply v2.37.308 and later. No workarounds are available; patching is required to remediate the issue.
Affected products
- Tanium Comply prior to Update 7 (v2.37.308)
Timeline
- 2026-09-09: disclosed