Impact
Tanium identified an improper access control flaw in its Comply component that can let a user bypass intended permissions, potentially accessing or modifying data or functionality beyond their authorized scope. This flaw is classified as CWE-639, reflecting a weakness in privilege management that could lead to unauthorized use of system capabilities.
Affected Systems
The vulnerability affects Tanium's Comply product. No specific version information is provided, so all installations of Comply should be evaluated until further details are released by Tanium.
Risk and Exploitability
The CVSS score of 5.4 indicates medium severity, and the absence of an EPSS value means no current estimate of exploit likelihood is available. The vulnerability is not catalogued in the CISA KEV list. While the exact attack vector is not specified, it is inferred that exploitation would require authenticated access or a privilege escalation step, so the threat is limited to environments where users have sufficient credentials to reach the affected functionality. Given the medium severity and uncertain exploit potential, organizations should treat this as a moderate risk pending a vendor fix.
OpenCVE Enrichment