Impact
An improper access control flaw exists in Tanium Comply that could allow an authenticated or potentially unauthenticated user to read or modify data beyond their intended scope, as identified by CWE-862. This violation could result in disclosure of protected information, unauthorized data manipulation, or elevated privileges within the Comply environment, thereby compromising confidentiality and integrity of assets managed by the system.
Affected Systems
The vulnerability affects Tanium Comply, a product from Tanium. All deployments of this product that have not yet incorporated the vendor’s security update are potentially exposed; specific affected versions were not disclosed by the vendor.
Risk and Exploitability
The flaw carries a CVSS score of 8.1, indicating high severity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. Based on the product’s typical remote access model, the likely attack vector is through network or web interfaces, possibly requiring an authenticated session or exploiting default access settings.
OpenCVE Enrichment