Impact
The vulnerability is an improper access control flaw in Tanium Comply that allows an attacker with limited or legitimate credentials to gain unauthorized access to sensitive data or perform privileged operations beyond the scope of their role. This can lead to disclosure or tampering of confidential information and degrade system integrity. The flaw is classified as CWE‑863, indicating that authorization checks are missing or insufficient.
Affected Systems
Tanium Comply is affected. No specific version numbers are listed in the advisory, so any deployment using Tanium Comply should verify if it is potentially impacted. The advisory URL provides details for affected configurations.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity and a significant risk of exploitation. The EPSS score is not available, so the likelihood of active exploitation is not quantified. The vulnerability is not included in CISA’s KEV catalog. Based on the nature of an improper access control flaw, the likely attack vector is through authenticated API calls or user actions within the application. An attacker who can authenticate to the system, possibly with a low‑privilege account, may exploit the missing authorization checks to elevate privileges or access restricted data.
OpenCVE Enrichment