Impact
The flaw is an improper access control that can enable a user without adequate permissions to read or manipulate sensitive information stored in Tanium Comply. The weakness is identified as CWE-639, which typically allows a session or account with insufficient privileges to bypass restrictions and access data they should not see. The resulting loss of confidentiality could expose confidential corporate or government data and potentially compromise operational decision making.
Affected Systems
The vulnerability affects Tanium Comply, but no specific product version is listed; the flaw applies to the current installation as distributed by Tanium. Administrators should verify that the deployed instance is identified as a Tanium Comply product (any version) before applying remediation steps.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate severity, and there is no EPSS data available to gauge real‑world exploitation frequency. The vulnerability is not listed in CISA’s KEV catalog, suggesting it has not yet been widely exploited. Because the weakness allows unauthorized data access, the risk is significant for organizations that rely on stringent segregation of data. Attackers with access to the network or local user accounts having minimal privileges could exploit the flaw by querying or setting parameters that expose protected fields.
OpenCVE Enrichment