Description
Tanium addressed an improper access controls vulnerability in Comply.
Published: 2026-09-09
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access to Sensitive Information and Operations
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is an improper access control flaw in Tanium Comply that allows an attacker with limited or legitimate credentials to gain unauthorized access to sensitive data or perform privileged operations beyond the scope of their role. This can lead to disclosure or tampering of confidential information and degrade system integrity. The flaw is classified as CWE‑863, indicating that authorization checks are missing or insufficient.

Affected Systems

Tanium Comply is affected. No specific version numbers are listed in the advisory, so any deployment using Tanium Comply should verify if it is potentially impacted. The advisory URL provides details for affected configurations.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity and a significant risk of exploitation. The EPSS score is not available, so the likelihood of active exploitation is not quantified. The vulnerability is not included in CISA’s KEV catalog. Based on the nature of an improper access control flaw, the likely attack vector is through authenticated API calls or user actions within the application. An attacker who can authenticate to the system, possibly with a low‑privilege account, may exploit the missing authorization checks to elevate privileges or access restricted data.

Generated by OpenCVE AI on September 9, 2026 at 04:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the latest Tanium Comply update that addresses the access control issue as per the Tanium advisory referenced at security.tanium.com/TAN-2026-037.
  • Confirm that role‑based access controls are correctly configured so that users have only the permissions necessary for their job functions.
  • Where feasible, temporarily restrict or disable exposed endpoints or functionality that are affected by the flaw until the patch is applied.

Generated by OpenCVE AI on September 9, 2026 at 04:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 16 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:tanium:comply:*:*:*:*:*:*:*:*

Fri, 11 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Tanium
Tanium comply
Vendors & Products Tanium
Tanium comply

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Description Tanium addressed an improper access controls vulnerability in Comply.
Title Tanium addressed an improper access controls vulnerability in Comply.
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Tanium

Published:

Updated: 2026-09-09T16:10:31.547Z

Reserved: 2026-09-08T19:06:30.349Z

Link: CVE-2026-87075

cve-icon Vulnrichment

Updated: 2026-09-09T16:04:50.486Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T03:17:26.953

Modified: 2026-09-16T15:25:10.750

Link: CVE-2026-87075

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T13:15:14Z

Weaknesses