Description
Tanium addressed an improper access controls vulnerability in Comply.
Published: 2026-09-09
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access / Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

Tanium identified an improper access control flaw in its Comply component that can let a user bypass intended permissions, potentially accessing or modifying data or functionality beyond their authorized scope. This flaw is classified as CWE-639, reflecting a weakness in privilege management that could lead to unauthorized use of system capabilities.

Affected Systems

The vulnerability affects Tanium's Comply product. No specific version information is provided, so all installations of Comply should be evaluated until further details are released by Tanium.

Risk and Exploitability

The CVSS score of 5.4 indicates medium severity, and the absence of an EPSS value means no current estimate of exploit likelihood is available. The vulnerability is not catalogued in the CISA KEV list. While the exact attack vector is not specified, it is inferred that exploitation would require authenticated access or a privilege escalation step, so the threat is limited to environments where users have sufficient credentials to reach the affected functionality. Given the medium severity and uncertain exploit potential, organizations should treat this as a moderate risk pending a vendor fix.

Generated by OpenCVE AI on September 9, 2026 at 04:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Tanium's website or security portal for a patch or update addressing the improper access control issue in Comply.
  • Apply the vendor-supplied fix as soon as it is released to remediate the privilege escalation flaw.
  • Conduct an internal access-control review to ensure no users possess permissions that exceed their job requirements, thereby reducing the window of opportunity for exploitation.

Generated by OpenCVE AI on September 9, 2026 at 04:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:tanium:comply:*:*:*:*:*:*:*:*

Thu, 10 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Tanium
Tanium comply
Vendors & Products Tanium
Tanium comply

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Description Tanium addressed an improper access controls vulnerability in Comply.
Title Tanium addressed an improper access controls vulnerability in Comply.
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Tanium

Published:

Updated: 2026-09-09T16:10:31.401Z

Reserved: 2026-09-08T17:59:41.117Z

Link: CVE-2026-87025

cve-icon Vulnrichment

Updated: 2026-09-09T16:04:47.894Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T03:17:25.437

Modified: 2026-09-16T15:24:42.843

Link: CVE-2026-87025

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:45:17Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key