Executive brief
Tanium Comply is a compliance and risk management tool used by enterprises to track and manage security configurations and policies. An improper access control vulnerability allows authenticated users with specific report-related permissions to access or modify compliance data beyond what their role should permit, potentially exposing sensitive compliance information or allowing unauthorized changes to compliance records.
Technical details
The vulnerability is an improper access control issue in Tanium Comply that affects authenticated users. Users with Comply Report Read, Comply Report Content Read, or Comply Report Write permissions can exploit this flaw to gain unauthorized read or write access to compliance data they should not be able to access. The vulnerability requires network access and valid credentials with specific permissions; no additional user interaction is needed. An authenticated attacker can read sensitive compliance data or modify compliance records within their organization. Patches are available via updates: v2.32.252+ (2025H1), v2.35.306+ (2025H2), and v2.37.308+ (2026H1).
Affected products
- Tanium Comply 2.32 to 2.32.251, 2.35 to 2.35.305, 2.37 to 2.37.307
Timeline
- 2026-09-09: disclosed