Impact
The vulnerability is an improper access control flaw in Tanium Comply that allows an attacker to bypass intended user restrictions and gain unauthorized access to sensitive data or functions, constituting an elevation of privilege.
Affected Systems
All installations of Tanium Comply could be impacted; no specific vulnerable versions are supplied, so every deployed instance of the product is potentially affected.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. EPSS information is unavailable, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a legitimate authenticated user exploiting improper permission checks to gain elevated privileges, but no exploit code or public proof‑of‑concept is currently referenced. The combination of moderate severity and the potential broad impact warrants prompt attention.
OpenCVE Enrichment