Description
Tanium addressed a path traversal vulnerability in Comply.
Published: 2026-09-09
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized File Access via Path Traversal
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in Tanium Comply permits an attacker to manipulate file path references to bypass directory boundaries. This can lead to reading or accessing files outside the intended directory, compromising confidentiality and potentially exposing sensitive data stored on the server. The weakness is a classic path traversal flaw, identified as a high-severity flaw.

Affected Systems

The affected product is Tanium Comply, as specified by the vendor and product name in the CNA listing. No specific version ranges are listed in the data, so administrators should verify whether their current deployment of Tanium Comply is affected.

Risk and Exploitability

With a CVSS score of 8.5, the potential impact is significant. The EPSS score is not available, but the flaw is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. Nonetheless, path traversal vulnerabilities can be exploited remotely through specially crafted requests, so the risk remains high and the likelihood of exploitation is non‑negligible.

Generated by OpenCVE AI on September 9, 2026 at 04:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Tanium Comply update that includes the path traversal fix as published by Tanium.
  • Reconfigure the application to restrict file system access only to designated directories, removing any ability to resolve paths outside those folders.
  • Disable or remove any unneeded file download or retrieval endpoints in the Comply configuration to limit the attack surface.

Generated by OpenCVE AI on September 9, 2026 at 04:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:tanium:comply:*:*:*:*:*:*:*:*

Fri, 11 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Tanium
Tanium comply
Vendors & Products Tanium
Tanium comply

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Description Tanium addressed a path traversal vulnerability in Comply.
Title Tanium addressed a path traversal vulnerability in Comply.
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Tanium

Published:

Updated: 2026-09-09T16:10:29.482Z

Reserved: 2026-09-08T17:42:30.300Z

Link: CVE-2026-87023

cve-icon Vulnrichment

Updated: 2026-09-09T16:04:17.491Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T03:17:25.323

Modified: 2026-09-16T15:24:39.967

Link: CVE-2026-87023

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T14:00:08Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')