Description
Tanium addressed a SQL injection vulnerability in Comply.
Published: 2026-09-09
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: SQL injection allowing unauthorized data access
Action: Patch Now
AI Analysis

Impact

The vulnerability in Tanium Comply allows an attacker to inject arbitrary SQL statements into database queries because input is not properly validated or parameterized. This weakness is classified as CWE-89 and could enable attackers to read, modify, or delete sensitive data stored in the Comply database, potentially leading to a data breach or disruption of services.

Affected Systems

Affected systems are Tanium Comply installations. No specific product versions are listed in the advisory, so any deployment of Tanium Comply is potentially vulnerable unless more recent releases are confirmed to include the fix.

Risk and Exploitability

The CVSS score of 8.3 indicates a high severity, while the EPSS score is not available, so the current guess on exploitation likelihood is unknown, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is through the exposed web or API interface that accepts unfiltered input; thus remote attackers could exploit the flaw without local privileges, although exact prerequisites are not detailed in the advisory.

Generated by OpenCVE AI on September 9, 2026 at 04:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Tanium Comply patch that addresses the SQL injection flaw, as identified in the TAN-2026-042 advisory
  • If a patch is not yet available, restrict all external access to the Comply web interface to trusted IP ranges until the fix is deployed
  • Modify any custom database code to use parameterized queries or prepared statements to prevent injection of malicious SQL
  • Monitor database logs for irregular query patterns that may indicate injection attempts

Generated by OpenCVE AI on September 9, 2026 at 04:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:tanium:comply:*:*:*:*:*:*:*:*

Thu, 10 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Tanium
Tanium comply
Vendors & Products Tanium
Tanium comply

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Description Tanium addressed a SQL injection vulnerability in Comply.
Title Tanium addressed a SQL injection vulnerability in Comply.
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Tanium

Published:

Updated: 2026-09-09T16:10:29.924Z

Reserved: 2026-09-08T18:28:45.935Z

Link: CVE-2026-87034

cve-icon Vulnrichment

Updated: 2026-09-09T16:04:24.886Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T03:17:25.897

Modified: 2026-09-16T15:23:51.110

Link: CVE-2026-87034

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:15:06Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')