Junglewise Threat Intelligence

CVE-2026-87033: Tanium Comply improper access control in network reports

CVE-2026-87033 · Severity: medium · CVSS 5.4 · Published 2026-09-09

Technologies: Tanium Comply. Vendors: Tanium.

Executive brief

Tanium Comply, a compliance management tool, contains an access control vulnerability that allows authenticated users with report-writing permissions to modify network reports outside their assigned content areas. An attacker with valid credentials and appropriate permissions could alter compliance reports, potentially leading to incorrect or false compliance data and unauthorized modifications to organizational records.

Technical details

The vulnerability is an improper access control issue in Tanium Comply that fails to properly validate authorization boundaries when modifying network reports. An authenticated user possessing the "Comply Report Write" permission can modify any network report regardless of content set ownership, bypassing intended access restrictions. The attack requires valid Tanium credentials and the specific "Comply Report Write" permission. An attacker can achieve unauthorized modification of compliance data across the organization. Patches are available: Comply v2.32.252 and later (2025H1), v2.35.306 and later (2025H2), and v2.37.308 and later (2026H1).

Affected products

  • Tanium Comply 2.32 to 2.32.252 (2025H1), 2.35 to 2.35.306 (2025H2), 2.37 to 2.37.308 (2026H1)

Timeline

  • 2026-09-09: disclosed

References

Related threats