Description
Tanium addressed an improper access controls vulnerability in Comply.
Published: 2026-09-09
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access to Protected Data
Action: Apply Patch
AI Analysis

Impact

Tanium reported an improper access control flaw in its Comply product, identified as CWE‑639, that permits a user lacking proper authorization to view or manipulate data otherwise protected. The flaw could enable attackers to read sensitive information or perform actions beyond their assigned role. No additional details about the specific data or functionality affected are provided in the entry.

Affected Systems

The vulnerability impacts the Tanium Comply product. No specific versions are listed; organizations should verify the presence of the issue in all deployed instances.

Risk and Exploitability

The CVSS base score of 4.3 indicates low‑to‑moderate severity. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog, suggesting limited observed exploitation to date. Attack details are not disclosed, so the vector and conditions for exploitation remain unspecified.

Generated by OpenCVE AI on September 9, 2026 at 04:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch or update to Tanium Comply that addresses the access control flaw.
  • Review and enforce least‑privilege access controls for all users and roles within Comply.
  • Conduct periodic privilege and permission audits to confirm that no users have unnecessary access to sensitive data.

Generated by OpenCVE AI on September 9, 2026 at 04:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:tanium:comply:*:*:*:*:*:*:*:*

Fri, 11 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Tanium
Tanium comply
Vendors & Products Tanium
Tanium comply

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Description Tanium addressed an improper access controls vulnerability in Comply.
Title Tanium addressed an improper access controls vulnerability in Comply.
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Tanium

Published:

Updated: 2026-09-09T16:10:31.830Z

Reserved: 2026-09-08T17:02:37.401Z

Link: CVE-2026-87019

cve-icon Vulnrichment

Updated: 2026-09-09T16:04:55.971Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T03:17:25.090

Modified: 2026-09-16T15:24:31.923

Link: CVE-2026-87019

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T23:45:17Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key