Impact
Tanium reported an improper access control flaw in its Comply product, identified as CWE‑639, that permits a user lacking proper authorization to view or manipulate data otherwise protected. The flaw could enable attackers to read sensitive information or perform actions beyond their assigned role. No additional details about the specific data or functionality affected are provided in the entry.
Affected Systems
The vulnerability impacts the Tanium Comply product. No specific versions are listed; organizations should verify the presence of the issue in all deployed instances.
Risk and Exploitability
The CVSS base score of 4.3 indicates low‑to‑moderate severity. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog, suggesting limited observed exploitation to date. Attack details are not disclosed, so the vector and conditions for exploitation remain unspecified.
OpenCVE Enrichment