CVE-2026-87075
largeIncorrect Authorization Flaw in Tanium Comply (CVSS 8.1)
Tanium has addressed an improper access-controls vulnerability (CWE-863, incorrect authorization) in Comply, the compliance benchmarking and assessment module of the Tanium endpoint management platform. The flaw is triggered when a remote actor with low-privileged access to the affected component sends requests without user interaction and performs actions outside the scope their authorization should permit. Per the CVSS 3.1 vector, there is no confidentiality impact, but the attacker can gain high impact on integrity and availability, such as altering data or disrupting the Comply service. Organizations running Tanium Comply are affected, and Tanium has shipped a patched release, though fixed version numbers are not stated in the available data. There is no known public proof-of-concept, the issue is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at roughly 0.2%, so no exploitation is currently known.
What to do: Update Tanium Comply to the patched release identified in Tanium's security advisory, since no fixed version number is given in the available data. Because the flaw requires low-privileged network access (PR:L), review which accounts and integrations hold low-privilege access to Comply and tighten those permissions, and restrict network exposure of the Tanium console/API to trusted management networks. Check for signs of unauthorized changes to compliance configurations or service disruption, and watch Tanium's advisory for updates.
| Tanium Comply | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Tanium addressed an improper access controls vulnerability in Comply.
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.