Executive brief
Tanium Comply is a compliance and policy management service that works with the Tanium Client to enforce security controls across enterprise systems. A SQL injection vulnerability could allow an attacker with privileged access on a system running the Tanium Client to manipulate SQL queries executed by the Comply service, potentially compromising the integrity of compliance policies and exposing sensitive configuration data.
Technical details
The vulnerability is a SQL injection flaw in Tanium Comply that permits attackers to tamper with SQL queries executed by the service. The attack requires privileged access to a system running the Tanium Client and user interaction (CVSS vector: AV:N/AC:H/PR:N/UI:R). Successful exploitation grants an attacker the ability to read, modify, and potentially delete data in the underlying database, affecting confidentiality, integrity, and availability. Patches are available in Update 24 for v2.32, Update 14 for v2.35, and Update 7 for v2.37 releases.
Affected products
- Tanium Comply v2.32 through v2.32.251 (2025H1), v2.35 through v2.35.305 (2025H2), v2.37 through v2.37.307 (2026H1)
Timeline
- 2026-09-09: disclosed: CVE-2026-87034 published on NVD
- 2026-09-09: patched: Updates released: v2.32.252 (Update 24), v2.35.306 (Update 14), v2.37.308 (Update 7)