CVE-2025-15340: Tanium addressed an incorrect default permissions vulnerability in Comply.
Published Feb 5, 2026
·Updated
Tanium addressed an incorrect default permissions vulnerability in Comply.
Affected Software
3 affected components
Tanium Comply>=2.24.0<2.24.159
Tanium Comply>=2.29.0<2.29.124
Tanium Comply>=2.32.0<2.32.155
Event History
Feb 5, 2026
CVE Published
via MITRE·06:16 PM
Data Sourced
via MITRE·06:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-15340?
CVE-2025-15340 is classified as a medium severity vulnerability due to incorrect default permissions in Tanium Comply.
2
How do I fix CVE-2025-15340?
To fix CVE-2025-15340, update Tanium Comply to the latest version that addresses this incorrect default permissions vulnerability.
3
What versions of Tanium Comply are affected by CVE-2025-15340?
CVE-2025-15340 affects Tanium Comply versions from 2.24.0 to 2.24.159, 2.29.0 to 2.29.124, and 2.32.0 to 2.32.155.
4
What are the potential risks associated with CVE-2025-15340?
The potential risks associated with CVE-2025-15340 include unauthorized access to sensitive compliance settings and data.
5
Has Tanium released any guidance on CVE-2025-15340?
Yes, Tanium has released guidance regarding CVE-2025-15340, advising users to update their affected software to mitigate the vulnerability.