ZeroHour

CVE-2026-87034

large

SQL Injection Vulnerability in Tanium Comply Module

CVSS 3.1
8.3 high
EPSS
<1%p9
Published
()
Modified
AI analysis

CVE-2026-87034 is a SQL injection flaw (CWE-89) in Comply, a compliance assessment module of the Tanium endpoint management platform. According to the CVSS 3.1 vector, it is reachable over the network with no privileges required, though exploitation involves high attack complexity and user interaction, and the scope-changed designation indicates successful injection may impact components beyond the vulnerable one. A successful attacker could achieve high-impact effects on confidentiality, integrity, and availability — typically reading or tampering with backend data managed by the module and potentially disrupting Tanium operations. Organizations running the Tanium Comply module are affected; specific vulnerable and fixed version ranges were not provided in the available data. There is no evidence of exploitation in the wild, no known public proof-of-concept, and the issue is not listed in CISA's KEV catalog.

What to do: Deploy the patched Comply release referenced in Tanium's security advisory (fixed version numbers are not stated in the available data), and verify whether the Comply module is installed or enabled in your Tanium deployment. In the meantime, restrict untrusted network and user access to the Tanium console/interfaces that front the Comply module. Watch for updated Tanium advisory details, since no public proof-of-concept or in-the-wild exploitation is currently known.

Affected
Tanium Comply (Tanium platform module)
Estimated exposure
large≈100,000–1,000,000 endpoints at organizations running the Tanium Comply module (Tanium's overall install base spans millions of endpoints); exact module usage… — Tanium is widely deployed in large enterprises and government agencies (a majority of Fortune 100 firms and numerous US federal agencies), but only deployments with the Comply module enabled are in scope, so the estimate scales Tanium's…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Tanium addressed a SQL injection vulnerability in Comply.

Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.