Junglewise Threat Intelligence

CVE-2026-87030: Tanium Comply path traversal arbitrary file deletion

CVE-2026-87030 · Severity: high · CVSS 8.5 · Published 2026-09-09

Technologies: Tanium Comply. Vendors: Tanium.

Executive brief

Tanium Comply, a configuration management and compliance tool, contains a path traversal vulnerability that allows authenticated users with specific administrative permissions to delete arbitrary files on the server. An attacker with these permissions could damage system integrity or disrupt operations by removing critical files, potentially causing service unavailability or data loss.

Technical details

This is a path traversal vulnerability (CWE-22) in Tanium Comply that allows authenticated users to access and manipulate files outside intended directories. The vulnerability requires the attacker to have Comply Deployment Write permission and authenticate to the system. By exploiting this vulnerability, an attacker can delete arbitrary files on the Tanium Module Server, affecting confidentiality through potential information disclosure and integrity through file deletion. Patches are available: version 2.32.252 or later (2025H1), version 2.35.306 or later (2025H2), and version 2.37.308 or later (2026H1).

Affected products

  • Tanium Comply 2.25-2.32.251, 2.35-2.35.305, 2.37-2.37.307

Timeline

  • 2026-09-09: disclosed
  • 2026-09-09: patched: Patches available for all affected releases

References

Related threats