ZeroHour

CVE-2026-87036

moderate

Improper Access Controls in Tanium Comply

CVSS 3.1
8.1 high
EPSS
<1%p11
Published
()
Modified
AI analysis

Tanium has addressed an improper access controls flaw in its Comply module, classified as CWE-862 (missing authorization), meaning the module fails to properly verify a user's permissions before performing actions. Because the CVSS vector requires only low privileges (PR:L) and no user interaction, an attacker who already holds a low-privileged, authenticated account or session with the Comply component can send a crafted network request that the module processes without an adequate authorization check. The CVSS scoring (C:N/I:H/A:H) indicates the attacker gains the ability to modify or tamper with data and potentially disrupt Comply operations, with no direct confidentiality loss. Any organization running Tanium with the Comply module deployed is potentially affected; specific affected and fixed version ranges were not disclosed in the provided data. There is currently no known exploitation: no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS estimates only a 0.2% probability of exploitation in the next 30 days.

What to do: Apply the Comply update provided by Tanium and consult Tanium's advisory for the exact affected and fixed version ranges, since these were not disclosed in the source data. In the meantime, restrict and review accounts with access to the Comply module, and audit Comply configuration and data for unexplained modifications or service disruption. With no known exploitation or public PoC, patching within normal maintenance windows is reasonable, but prioritize internet-facing or broadly shared Tanium console deployments.

Affected
Tanium Comply
Estimated exposure
moderate≈1,000–10,000 deployments of the Comply module (exact count unknown) — Tanium's platform is deployed at thousands of large enterprises and government agencies, but Comply is an optional compliance module used by only a subset of customers, and this flaw is in the module rather than in every managed endpoint.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Tanium addressed an improper access controls vulnerability in Comply.

Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.