Description
Tanium addressed an improper access controls vulnerability in Comply.
Published: 2026-09-09
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Improper Access Control
Action: Apply Patch
AI Analysis

Impact

The flaw is an improper access control that can enable a user without adequate permissions to read or manipulate sensitive information stored in Tanium Comply. The weakness is identified as CWE-639, which typically allows a session or account with insufficient privileges to bypass restrictions and access data they should not see. The resulting loss of confidentiality could expose confidential corporate or government data and potentially compromise operational decision making.

Affected Systems

The vulnerability affects Tanium Comply, but no specific product version is listed; the flaw applies to the current installation as distributed by Tanium. Administrators should verify that the deployed instance is identified as a Tanium Comply product (any version) before applying remediation steps.

Risk and Exploitability

The CVSS score of 6.3 indicates a moderate severity, and there is no EPSS data available to gauge real‑world exploitation frequency. The vulnerability is not listed in CISA’s KEV catalog, suggesting it has not yet been widely exploited. Because the weakness allows unauthorized data access, the risk is significant for organizations that rely on stringent segregation of data. Attackers with access to the network or local user accounts having minimal privileges could exploit the flaw by querying or setting parameters that expose protected fields.

Generated by OpenCVE AI on September 9, 2026 at 04:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Tanium Comply patch or upgrade to a version that resolves the access control issue
  • Implement role‑based access controls and validate that only authorized users have permissions to view or modify sensitive data
  • Audit access logs for anomalous read attempts and enforce least‑privilege principles across the deployment

Generated by OpenCVE AI on September 9, 2026 at 04:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:tanium:comply:*:*:*:*:*:*:*:*

Thu, 10 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Tanium
Tanium comply
Vendors & Products Tanium
Tanium comply

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Description Tanium addressed an improper access controls vulnerability in Comply.
Title Tanium addressed an improper access controls vulnerability in Comply.
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Tanium

Published:

Updated: 2026-09-09T16:10:31.692Z

Reserved: 2026-09-08T18:48:32.711Z

Link: CVE-2026-87047

cve-icon Vulnrichment

Updated: 2026-09-09T16:04:52.835Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T03:17:26.493

Modified: 2026-09-16T15:24:28.323

Link: CVE-2026-87047

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:45:17Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key