CVE-2026-87072
moderateImproper Access Control in Tanium Comply Exposes Compliance Data
Tanium Comply, the compliance-management module of the Tanium endpoint platform, contained a missing-authorization flaw (CWE-862) in which certain actions were not properly checked against the requester's permissions. The flaw is triggered over the network by a user who already holds low-privileged credentials on the platform and sends a request to an insufficiently protected Comply function; no user interaction is required. A successful attacker gains high-confidence read access to data they should not see — such as compliance and endpoint-configuration information collected by Comply — plus limited ability to alter Comply data, with no availability impact. Organizations that deploy the Tanium platform with the Comply module are affected, and any low-privileged authenticated user reaching the module could exploit it. There is no evidence of active exploitation: the issue is not in CISA KEV, EPSS is a low 0.2% (7th percentile), and no public proof-of-concept is known.
What to do: Upgrade the Tanium Comply module to the patched release identified in Tanium's security advisory, since no fixed version number is provided in this data. Until then, limit which low-privileged platform accounts can reach Comply endpoints and review permissions on compliance data. Check your deployed Comply version in the Tanium console and monitor the vendor bulletin for exploitation updates.
| Tanium Comply | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Tanium addressed an improper access controls vulnerability in Comply.
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.