Impact
Tanium Comply contains an improper access control flaw that can enable an attacker to view or modify data beyond the intended permissions. The weakness is classified as CWE‑639, meaning a legitimate user might gain unauthorized privileges, potentially compromising confidential information within the Comply platform. The CVSS score of 5.4 indicates a moderate impact if exploited.
Affected Systems
The vulnerability is present in Tanium’s Comply product. No specific version numbers are listed in the available data, so all installations that have not applied the vendor’s fix are potentially affected.
Risk and Exploitability
With no EPSS score provided, the precise likelihood of exploitation cannot be quantified, and the issue is not listed in the CISA KEV catalog. The CVSS score of 5.4 reflects medium severity, but because the flaw allows privilege escalation within the Comply software, a malicious actor with network or user access could leverage it, especially if the system is exposed to potential compromised credentials or has lax role definitions. The attack vector would most likely involve unauthorized access to the application’s interfaces or APIs.
OpenCVE Enrichment