Junglewise Threat Intelligence

CVE-2026-87037: Tanium Comply improper access control

CVE-2026-87037 · Severity: medium · CVSS 5.4 · Published 2026-09-09

Technologies: Tanium Comply. Vendors: Tanium.

Executive brief

Tanium Comply is a compliance management and reporting platform used by enterprises to track and enforce security policies. An improper access control vulnerability allows authenticated users with report-writing permissions to access and modify data they should not be able to reach, potentially exposing sensitive compliance information and enabling unauthorized changes to reports.

Technical details

The vulnerability is an improper access control issue in Tanium Comply that allows authenticated users with the "comply report write" permission to bypass intended authorization checks. The flaw affects multiple release branches: 2025H1 (v2.32–v2.32.251), 2025H2 (v2.35–v2.35.305), and 2026H1 (v2.37–v2.37.307). Exploitation requires valid Tanium credentials and the specific report-write permission; no network authentication or user interaction is required beyond the initial login. An attacker can read and write data outside their authorized scope, compromising data integrity and confidentiality. Patches are available via product updates in all affected release branches.

Affected products

  • Tanium Comply 2.32–2.32.251 (2025H1); 2.35–2.35.305 (2025H2); 2.37–2.37.307 (2026H1)

Timeline

  • 2026-09-09: disclosed

References

Related threats