Impact
The vulnerability is an improper access control flaw in Tanium Comply that could allow attackers to gain unauthorized access to the application and view or modify compliance data. The weakness is addressed by CWE-863. An attacker who can exploit this may read or alter data that should be restricted to authorized users, impacting confidentiality and integrity of compliance information.
Affected Systems
The affected product is Tanium Comply. No specific version information was provided in the advisory.
Risk and Exploitability
The CVSS score is 4.3, indicating moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred to involve an authenticated attacker or an unauthorized user who can access the Comply interface, potentially allowing elevation of privileges or data exposure. Because the exploit pathway depends on the user who has access, the risk is moderate and mitigation is strongly recommended.
OpenCVE Enrichment