Description
Tanium addressed an improper access controls vulnerability in Comply.
Published: 2026-09-09
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch
AI Analysis

Impact

The vulnerability describes improper access controls in the Tanium Comply product, allowing users who lack appropriate privileges to gain unauthorized access to privileged functions. This could lead to unauthorized disclosure, modification, or destruction of information and elevation of user privileges. The exact attack vector is not detailed in the official description, so the exploitation path remains unclear but likely requires authenticated interactions with the Comply service.

Affected Systems

The Tanium Comply product is affected. No specific version information is provided; organizations should verify the installed version against vendor advisories.

Risk and Exploitability

With a CVSS score of 5.4, the vulnerability is considered moderate. The EPSS score is not available, and it is not listed in CISA's KEV catalog, indicating no publicly known exploitation at this time. The risk is moderate, and the likelihood of exploitation remains uncertain, particularly due to the lack of details on the attack vector. However, the moderate severity suggests that any exploitation could have meaningful impact on confidentiality or integrity if successful.

Generated by OpenCVE AI on September 9, 2026 at 04:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Tanium Comply update or vendor-specified patch that addresses the improper access control flaw.
  • Verify that role‑based access controls are correctly configured and enforce least privilege for all users interacting with Comply.
  • Schedule periodic reviews and audit logs for signs of unauthorized privileged activity, and adjust controls as needed.

Generated by OpenCVE AI on September 9, 2026 at 04:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:tanium:comply:*:*:*:*:*:*:*:*

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Tanium
Tanium comply
Vendors & Products Tanium
Tanium comply

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Description Tanium addressed an improper access controls vulnerability in Comply.
Title Tanium addressed an improper access controls vulnerability in Comply.
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Tanium

Published:

Updated: 2026-09-09T16:10:32.131Z

Reserved: 2026-09-08T18:36:36.358Z

Link: CVE-2026-87037

cve-icon Vulnrichment

Updated: 2026-09-09T16:05:00.499Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T03:17:26.257

Modified: 2026-09-16T15:24:19.167

Link: CVE-2026-87037

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:51:15Z

Weaknesses