Description
Tanium addressed an improper access controls vulnerability in Comply.
Published: 2026-09-09
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access
Action: Assess Impact
AI Analysis

Impact

An improper access control flaw exists in Tanium Comply that could allow an authenticated or potentially unauthenticated user to read or modify data beyond their intended scope, as identified by CWE-862. This violation could result in disclosure of protected information, unauthorized data manipulation, or elevated privileges within the Comply environment, thereby compromising confidentiality and integrity of assets managed by the system.

Affected Systems

The vulnerability affects Tanium Comply, a product from Tanium. All deployments of this product that have not yet incorporated the vendor’s security update are potentially exposed; specific affected versions were not disclosed by the vendor.

Risk and Exploitability

The flaw carries a CVSS score of 8.1, indicating high severity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. Based on the product’s typical remote access model, the likely attack vector is through network or web interfaces, possibly requiring an authenticated session or exploiting default access settings.

Generated by OpenCVE AI on September 9, 2026 at 04:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Tanium Comply security update that addresses the access control flaw
  • Review and tighten role‑based permissions in the Comply configuration to ensure least privilege
  • Conduct an internal audit of user accounts and permissions to confirm that no unauthorized access rights remain

Generated by OpenCVE AI on September 9, 2026 at 04:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:tanium:comply:*:*:*:*:*:*:*:*

Thu, 10 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Tanium
Tanium comply
Vendors & Products Tanium
Tanium comply

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Description Tanium addressed an improper access controls vulnerability in Comply.
Title Tanium addressed an improper access controls vulnerability in Comply.
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Tanium

Published:

Updated: 2026-09-09T16:10:29.171Z

Reserved: 2026-09-08T18:32:07.122Z

Link: CVE-2026-87036

cve-icon Vulnrichment

Updated: 2026-09-09T16:04:11.031Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T03:17:26.143

Modified: 2026-09-16T15:24:12.643

Link: CVE-2026-87036

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:15:06Z

Weaknesses