Executive brief
Tanium Comply is a compliance and security scanning tool used to assess endpoint vulnerabilities across enterprise networks. An authenticated user with specific reporting and scanning permissions could exploit an access control flaw to execute security scans against endpoints they are not authorized to manage, potentially exposing sensitive systems or gathering unauthorized information.
Technical details
The vulnerability is an improper access controls flaw in Tanium Comply that fails to properly validate authorization boundaries for scan execution. An authenticated attacker with the "Comply Report Write" and "Comply Scan Execute" permissions can execute scans against endpoints beyond their assigned management scope. The attack requires valid Tanium credentials and the specific permissions noted, but no user interaction. Exploitation allows unauthorized scanning of systems the attacker lacks management rights over. Patches are available for all supported release branches: v2.32.252+, v2.35.306+, and v2.37.308+.
Affected products
- Tanium Comply 2.32 to 2.32.252, 2.35 to 2.35.306, 2.37 to 2.37.308
Timeline
- 2026-09-09: disclosed