Junglewise Threat Intelligence

CVE-2026-87023: Tanium Comply path traversal vulnerability

CVE-2026-87023 · Severity: high · CVSS 8.5 · Published 2026-09-09

Technologies: Tanium Comply. Vendors: Tanium.

Executive brief

Tanium Comply, a compliance reporting and assessment tool, contains a path traversal vulnerability that allows authenticated users with specific permissions to read files and data they should not have access to. An attacker with valid credentials and the "Comply Report Content" permission can exploit this to gain unauthorized access to sensitive information across the system.

Technical details

The vulnerability is a path traversal issue in Tanium Comply that allows an authenticated attacker to access arbitrary files or data outside their intended scope. The attack requires valid credentials and the "Comply Report Content" permission role. Attack vector is network-based with low complexity and no user interaction required. A successful exploit results in high confidentiality impact (unauthorized read access to restricted data) and low availability impact. Patches are available across all affected release lines: v2.32.252+, v2.35.306+, and v2.37.308+.

Affected products

  • Tanium Comply 2.32 to 2.32.252, 2.35 to 2.35.306, 2.37 to 2.37.308

Timeline

  • 2026-09-09: disclosed
  • 2026-09-09: patched: Updates available for all affected releases (v2.32.252, v2.35.306, v2.37.308 and later)

References

Related threats