CVE-2026-87036
moderateImproper Access Controls in Tanium Comply
Tanium has addressed an improper access controls flaw in its Comply module, classified as CWE-862 (missing authorization), meaning the module fails to properly verify a user's permissions before performing actions. Because the CVSS vector requires only low privileges (PR:L) and no user interaction, an attacker who already holds a low-privileged, authenticated account or session with the Comply component can send a crafted network request that the module processes without an adequate authorization check. The CVSS scoring (C:N/I:H/A:H) indicates the attacker gains the ability to modify or tamper with data and potentially disrupt Comply operations, with no direct confidentiality loss. Any organization running Tanium with the Comply module deployed is potentially affected; specific affected and fixed version ranges were not disclosed in the provided data. There is currently no known exploitation: no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS estimates only a 0.2% probability of exploitation in the next 30 days.
What to do: Apply the Comply update provided by Tanium and consult Tanium's advisory for the exact affected and fixed version ranges, since these were not disclosed in the source data. In the meantime, restrict and review accounts with access to the Comply module, and audit Comply configuration and data for unexplained modifications or service disruption. With no known exploitation or public PoC, patching within normal maintenance windows is reasonable, but prioritize internet-facing or broadly shared Tanium console deployments.
| Tanium Comply | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Tanium addressed an improper access controls vulnerability in Comply.
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.