ZeroHour

CVE-2026-87021

moderate

High-Privilege Code Execution Flaw in Tanium Comply (Template Injection)

CVSS 3.1
7.2 high
EPSS
<1%p30
Published
()
Modified
AI analysis

Tanium has patched an unauthorized code execution vulnerability in its Comply compliance module, classified as CWE-1336 (improper neutralization of special elements used in a template engine), which suggests a server-side template-injection flaw. According to the CVSS vector, an attacker exploits it over the network with low attack complexity but must already hold high privileges within the affected deployment, and no user interaction is required. Successful exploitation carries high impact to confidentiality, integrity, and availability, consistent with arbitrary code execution on the affected Tanium component. Only organizations running the Tanium Comply module are affected, and the available advisory data does not specify affected or fixed version numbers. There is no known exploitation: the flaw is absent from CISA KEV, has a modest EPSS score (0.4% probability of exploitation within 30 days, 30th percentile), and no public proof-of-concept exists.

What to do: If the Tanium Comply module is deployed in your environment, apply the patched release referenced in Tanium's security advisory, since no fixed version number is provided in the available data. Because exploitation requires high-privileged credentials, restrict administrative access to Tanium platform and module interfaces and review accounts with such access for misuse. Monitor Tanium's advisory for updated version details and any mitigation guidance.

Affected
Tanium Comply
Estimated exposure
moderate≈1,000–5,000 enterprise deployments of the Comply module (estimated) — Tanium is sold primarily to large enterprises and government agencies (a customer base on the order of thousands of organizations) and Comply is an optional licensed module typically deployed as a small number of server-side instances per…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Tanium addressed an unauthorized code execution vulnerability in Comply.

Weakness
CWE-1336
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.