Junglewise Threat Intelligence

CVE-2026-87025: Tanium Comply improper access controls in credentials

CVE-2026-87025 · Severity: medium · CVSS 5.4 · Published 2026-09-09

Technologies: Tanium Comply. Vendors: Tanium.

Executive brief

Tanium Comply is a compliance management tool that stores and manages security credentials. An authenticated user with credential-write permissions could exploit this vulnerability to create or modify credentials assigned to different organizational units, potentially gaining unauthorized access to systems and data those credentials protect.

Technical details

The vulnerability is an improper access controls flaw in Tanium Comply that fails to properly validate content set ownership when handling credential operations. An authenticated user with the Comply Credential Write permission can create or modify credentials belonging to a different content set than their own, bypassing intended access restrictions. The attack requires valid authentication and the target permission but no user interaction. Exploitation allows credential hijacking and lateral movement across different organizational contexts. Patches are available for all affected release lines: v2.32.252 (2025H1), v2.35.306 (2025H2), and v2.37.308 (2026H1).

Affected products

  • Tanium Comply 2.32 to 2.32.251; 2.35 to 2.35.305; 2.37 to 2.37.307

Timeline

  • 2026-09-09: disclosed

References

Related threats