ZeroHour

CVE-2026-87030

Authenticated Path Traversal in Tanium Comply

CVSS 3.1
8.5 high
EPSS
<1%p21
Published
()
Modified
AI analysis

Tanium Comply, the compliance-assessment module of the Tanium platform, contained a path traversal vulnerability (CWE-22) that Tanium has now patched. An attacker who holds low-privileged credentials on the system can submit crafted paths that escape the intended directory boundary; because the CVSS scope is 'changed', the traversal can cross into a neighboring security scope, yielding a high integrity impact (unauthorized file modification) and a low availability impact, with no confidentiality loss. The flaw is triggered over the network by authenticated, low-privilege input rather than by unauthenticated requests or user interaction. Any organization running the Tanium Comply module is in scope for the fix. There is no evidence of exploitation so far: the issue is not in CISA's KEV and no public proof-of-concept is known.

What to do: Deploy the Tanium-published update for Comply as soon as possible, confirming the fixed version in Tanium's advisory since no specific patched version is given in the disclosure data. Because exploitation requires low-privileged authenticated access, review which accounts can reach Comply and monitor for unexpected file modifications in or around the Comply installation. Re-run or verify compliance scans after patching to confirm no artifacts were tampered with.

Affected
Tanium Comply (compliance module of the Tanium platform)
Estimated exposure
unknown (plausibly thousands of enterprise deployments of the Comply module) — Tanium is deployed across thousands of enterprise customers managing millions of endpoints, but the vendor publishes no per-module install counts for Comply, so the number of vulnerable Comply deployments cannot be quantified from the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Tanium addressed a path traversal vulnerability in Comply.

Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L

In the news

No ingested article mentions this CVE yet.