CVE-2026-87023
largeAuthenticated Path Traversal in Tanium Comply Allows Sensitive File Reads
Tanium addressed a path traversal vulnerability (CWE-22) in its Comply compliance-assessment module, rated 8.5 (High) with the vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L. Per that vector, an attacker with low-privileged credentials can reach the flaw over the network with no user interaction, sending crafted input containing directory-traversal sequences that escape the intended file path when processed by Comply. The high confidentiality score and changed scope indicate the attacker can read sensitive files beyond the vulnerable component's normal boundary, with no direct integrity impact and only low availability impact. Any organization running the Tanium platform with the Comply module deployed is affected. There is no evidence of active exploitation: the flaw is not on CISA's KEV list and no public proof-of-concept is known.
What to do: Upgrade Tanium Comply to the patched release through the Tanium console, and check Tanium's advisory or release notes for the specific fixed version since none is listed in this data. Restrict which accounts can reach the Comply module and review the Comply server for sensitive files (configuration, keys, credentials) that an authenticated attacker could have read. Monitor Tanium channels and CISA KEV for updated guidance or evidence of exploitation.
| Tanium Comply | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Tanium addressed a path traversal vulnerability in Comply.
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.