ZeroHour

CVE-2026-87075

large

Incorrect Authorization Flaw in Tanium Comply (CVSS 8.1)

CVSS 3.1
8.1 high
EPSS
<1%p11
Published
()
Modified
AI analysis

Tanium has addressed an improper access-controls vulnerability (CWE-863, incorrect authorization) in Comply, the compliance benchmarking and assessment module of the Tanium endpoint management platform. The flaw is triggered when a remote actor with low-privileged access to the affected component sends requests without user interaction and performs actions outside the scope their authorization should permit. Per the CVSS 3.1 vector, there is no confidentiality impact, but the attacker can gain high impact on integrity and availability, such as altering data or disrupting the Comply service. Organizations running Tanium Comply are affected, and Tanium has shipped a patched release, though fixed version numbers are not stated in the available data. There is no known public proof-of-concept, the issue is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at roughly 0.2%, so no exploitation is currently known.

What to do: Update Tanium Comply to the patched release identified in Tanium's security advisory, since no fixed version number is given in the available data. Because the flaw requires low-privileged network access (PR:L), review which accounts and integrations hold low-privilege access to Comply and tighten those permissions, and restrict network exposure of the Tanium console/API to trusted management networks. Check for signs of unauthorized changes to compliance configurations or service disruption, and watch Tanium's advisory for updates.

Affected
Tanium Comply
Estimated exposure
large≈100k–1M managed endpoints across enterprise and government deployments running the Comply module (estimate) — Tanium is widely deployed in large enterprises and government agencies that manage tens of thousands to hundreds of thousands of endpoints each, and a subset of those customers runs the Comply compliance module, making an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Tanium addressed an improper access controls vulnerability in Comply.

Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.