Junglewise Threat Intelligence

CVE-2026-87019: Tanium Comply improper access control

CVE-2026-87019 · Severity: medium · CVSS 4.3 · Published 2026-09-09

Technologies: Tanium Comply. Vendors: Tanium.

Executive brief

Tanium Comply is a compliance and assessment management platform used to track and manage security configurations. An improper access control vulnerability allows authenticated users with the Comply Report Write permission to create or modify assessment configurations they should not be able to access, potentially compromising compliance posture and audit integrity.

Technical details

This is an improper access controls vulnerability in Tanium Comply that permits privilege escalation. An authenticated attacker with Comply Report Write permission can create or modify Comply assessment configurations beyond their intended authorization scope. The vulnerability is network-accessible and requires only valid user credentials with the specific permission. The impact is limited to integrity (configuration modification) with no confidentiality impact. Patches are available across all affected release branches: 2025H1 Update 24 (v2.32.252), 2025H2 Update 14 (v2.35.306), and 2026H1 Update 7 (v2.37.308).

Affected products

  • Tanium Comply 2025H1 prior to Update 24 (v2.32.252); 2025H2 prior to Update 14 (v2.35.306); 2026H1 prior to Update 7 (v2.37.308)

Timeline

  • 2026-09-09: disclosed

References

Related threats