Junglewise Threat Intelligence

CVE-2026-87036: Tanium Comply improper access controls in assessment deletion

CVE-2026-87036 · Severity: high · CVSS 8.1 · Published 2026-09-09

Technologies: Tanium Comply. Vendors: Tanium.

Executive brief

Tanium Comply is an enterprise compliance and configuration management platform used to assess and enforce security policies across organizations. A vulnerability in Comply allows authenticated users with specific report-writing permissions to delete assessments from the compliance database without proper authorization, potentially undermining audit trails and compliance records.

Technical details

An improper access control vulnerability in Tanium Comply allows authenticated users with the "comply report write" permission to delete assessments from the Comply database. The vulnerability has a CVSS 3.1 score of 8.1 (network-accessible, low complexity, requires low-privilege authentication but no user interaction). The attack vector is network-based and affects confidentiality, integrity, and availability. Affected versions include Comply 2.32–2.32.252 (2025H1), 2.35–2.35.306 (2025H2), and 2.37–2.37.308 (2026H1). Patches are available in Update 24 (v2.32.252+), Update 14 (v2.35.306+), and Update 7 (v2.37.308+) respectively.

Affected products

  • Tanium Comply 2.32–2.32.252, 2.35–2.35.306, 2.37–2.37.308

Timeline

  • 2026-09-09: disclosed

References

Related threats