CVE-2026-87021
moderateHigh-Privilege Code Execution Flaw in Tanium Comply (Template Injection)
Tanium has patched an unauthorized code execution vulnerability in its Comply compliance module, classified as CWE-1336 (improper neutralization of special elements used in a template engine), which suggests a server-side template-injection flaw. According to the CVSS vector, an attacker exploits it over the network with low attack complexity but must already hold high privileges within the affected deployment, and no user interaction is required. Successful exploitation carries high impact to confidentiality, integrity, and availability, consistent with arbitrary code execution on the affected Tanium component. Only organizations running the Tanium Comply module are affected, and the available advisory data does not specify affected or fixed version numbers. There is no known exploitation: the flaw is absent from CISA KEV, has a modest EPSS score (0.4% probability of exploitation within 30 days, 30th percentile), and no public proof-of-concept exists.
What to do: If the Tanium Comply module is deployed in your environment, apply the patched release referenced in Tanium's security advisory, since no fixed version number is provided in the available data. Because exploitation requires high-privileged credentials, restrict administrative access to Tanium platform and module interfaces and review accounts with such access for misuse. Monitor Tanium's advisory for updated version details and any mitigation guidance.
| Tanium Comply | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Tanium addressed an unauthorized code execution vulnerability in Comply.
- Weakness
- CWE-1336
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.