ZeroHour

CVE-2026-87072

moderate

Improper Access Control in Tanium Comply Exposes Compliance Data

CVSS 3.1
7.1 high
EPSS
<1%p7
Published
()
Modified
AI analysis

Tanium Comply, the compliance-management module of the Tanium endpoint platform, contained a missing-authorization flaw (CWE-862) in which certain actions were not properly checked against the requester's permissions. The flaw is triggered over the network by a user who already holds low-privileged credentials on the platform and sends a request to an insufficiently protected Comply function; no user interaction is required. A successful attacker gains high-confidence read access to data they should not see — such as compliance and endpoint-configuration information collected by Comply — plus limited ability to alter Comply data, with no availability impact. Organizations that deploy the Tanium platform with the Comply module are affected, and any low-privileged authenticated user reaching the module could exploit it. There is no evidence of active exploitation: the issue is not in CISA KEV, EPSS is a low 0.2% (7th percentile), and no public proof-of-concept is known.

What to do: Upgrade the Tanium Comply module to the patched release identified in Tanium's security advisory, since no fixed version number is provided in this data. Until then, limit which low-privileged platform accounts can reach Comply endpoints and review permissions on compliance data. Check your deployed Comply version in the Tanium console and monitor the vendor bulletin for exploitation updates.

Affected
Tanium Comply
Estimated exposure
moderate≈1,000–10,000 enterprise/government deployments of the Comply module (no public endpoint count) — Tanium sells almost exclusively to large enterprises and public-sector organizations (roughly 1,500+ customers, including major government agencies), and only the subset that runs the Comply module is affected, implying deployments in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Tanium addressed an improper access controls vulnerability in Comply.

Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.