CVE-2026-87034
largeSQL Injection Vulnerability in Tanium Comply Module
CVE-2026-87034 is a SQL injection flaw (CWE-89) in Comply, a compliance assessment module of the Tanium endpoint management platform. According to the CVSS 3.1 vector, it is reachable over the network with no privileges required, though exploitation involves high attack complexity and user interaction, and the scope-changed designation indicates successful injection may impact components beyond the vulnerable one. A successful attacker could achieve high-impact effects on confidentiality, integrity, and availability — typically reading or tampering with backend data managed by the module and potentially disrupting Tanium operations. Organizations running the Tanium Comply module are affected; specific vulnerable and fixed version ranges were not provided in the available data. There is no evidence of exploitation in the wild, no known public proof-of-concept, and the issue is not listed in CISA's KEV catalog.
What to do: Deploy the patched Comply release referenced in Tanium's security advisory (fixed version numbers are not stated in the available data), and verify whether the Comply module is installed or enabled in your Tanium deployment. In the meantime, restrict untrusted network and user access to the Tanium console/interfaces that front the Comply module. Watch for updated Tanium advisory details, since no public proof-of-concept or in-the-wild exploitation is currently known.
| Tanium Comply (Tanium platform module) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Tanium addressed a SQL injection vulnerability in Comply.
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.