Description
Tanium addressed a path traversal vulnerability in Comply.
Published: 2026-09-09
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote path traversal leading to secret or system file disclosure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a path traversal flaw that can allow an attacker to read arbitrary files on the server hosting Tanium Comply. By manipulating request paths, an attacker could access sensitive configuration files or other data that should not be exposed, potentially leading to data theft or further compromise. The weakness is categorized as CWE‑22, a classic example of path manipulation weaknesses.

Affected Systems

Tanium’s Comply application is affected. No specific product versions are listed in the CVE data, so all deployments of Tanium Comply are potentially vulnerable until a patch is applied.

Risk and Exploitability

The score of 8.5 on the CVSS scale indicates a high severity, and although the EPSS is not published, the flaw’s nature suggests a moderate exploitation probability. It is not currently listed in the CISA KEV catalog. The likely attack vector is remote, via HTTP or HTTPS requests to the Comply web service, where an attacker can craft a malicious path to exfiltrate files. Successful exploitation could expose confidential data or aid further attacks against the infrastructure.

Generated by OpenCVE AI on September 9, 2026 at 04:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Tanium Comply to the latest patch that resolves the path traversal flaw
  • If an immediate patch is unavailable, isolate the Comply service behind a Web Application Firewall and enforce strict access controls to block traversal attempts
  • Configure the server to reject any requests containing directory traversal sequences before the application processes them, and review file permissions to ensure sensitive data is not readable by the web process

Generated by OpenCVE AI on September 9, 2026 at 04:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:tanium:comply:*:*:*:*:*:*:*:*

Thu, 10 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Tanium
Tanium comply
Vendors & Products Tanium
Tanium comply

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Description Tanium addressed a path traversal vulnerability in Comply.
Title Tanium addressed a path traversal vulnerability in Comply.
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Tanium

Published:

Updated: 2026-09-09T16:10:31.105Z

Reserved: 2026-09-08T18:11:20.240Z

Link: CVE-2026-87030

cve-icon Vulnrichment

Updated: 2026-09-09T16:04:42.587Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T03:17:25.557

Modified: 2026-09-16T15:24:52.067

Link: CVE-2026-87030

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:45:17Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')