Executive brief
Tanium Comply is a compliance and assessment tool used to evaluate system security configurations. A flaw in access controls allows privileged users on systems running the Tanium Client to forge or alter compliance assessment results, potentially masking security issues and undermining the integrity of compliance reports.
Technical details
This vulnerability is an improper access control flaw in Tanium Comply affecting versions 2.32–2.37 across multiple release lines. An attacker with privileged local access to a system running the Tanium Client can create or modify Comply assessment scan results without proper authorization checks. The network attack vector (AV:N) combined with low attack complexity (AC:L) indicates the flaw may be reachable over the network with valid credentials (PR:L). The impact is high integrity (I:H), meaning attackers can tamper with assessment data. Patches are available for all affected release lines: v2.32.252, v2.35.306, and v2.37.308 or later.
Affected products
- Tanium Comply 2.32 to 2.32.252, 2.35 to 2.35.306, 2.37 to 2.37.308
Timeline
- 2026-09-09: disclosed
- 2026-09-09: patched: Updates available for all affected release lines