Executive brief
Tanium Comply is an enterprise compliance and configuration management platform used to assess and enforce security policies across organizations. A vulnerability in Comply allows authenticated users with specific report-writing permissions to delete assessments from the compliance database without proper authorization, potentially undermining audit trails and compliance records.
Technical details
An improper access control vulnerability in Tanium Comply allows authenticated users with the "comply report write" permission to delete assessments from the Comply database. The vulnerability has a CVSS 3.1 score of 8.1 (network-accessible, low complexity, requires low-privilege authentication but no user interaction). The attack vector is network-based and affects confidentiality, integrity, and availability. Affected versions include Comply 2.32–2.32.252 (2025H1), 2.35–2.35.306 (2025H2), and 2.37–2.37.308 (2026H1). Patches are available in Update 24 (v2.32.252+), Update 14 (v2.35.306+), and Update 7 (v2.37.308+) respectively.
Affected products
- Tanium Comply 2.32–2.32.252, 2.35–2.35.306, 2.37–2.37.308
Timeline
- 2026-09-09: disclosed