Junglewise Threat Intelligence

CVE-2026-87046: Tanium Comply improper access control vulnerability

CVE-2026-87046 · Severity: medium · CVSS 4.3 · Published 2026-09-09

Technologies: Tanium Comply. Vendors: Tanium.

Executive brief

Tanium Comply is a vulnerability management and compliance platform used by enterprises to identify and track security issues across their infrastructure. This vulnerability allows authenticated users with specific report-writing permissions to inappropriately modify vulnerability feed settings, potentially leading to incorrect or missing vulnerability data in compliance reports.

Technical details

This is an improper access control vulnerability in Tanium Comply that allows an authenticated user with the "comply report content write" permission to create or modify vulnerability feed settings beyond their intended authorization scope. The vulnerability requires valid authentication and a specific role permission, but no additional user interaction. An attacker with this permission could alter vulnerability feed configurations, potentially compromising the accuracy and integrity of vulnerability data used for compliance and security assessments. Patches are available for all affected release tracks: Update 24 for 2025H1, Update 14 for 2025H2, and Update 7 for 2026H1.

Affected products

  • Tanium Comply 2.32 to 2.32.252 (2025H1 prior to Update 24), 2.35 to 2.35.306 (2025H2 prior to Update 14), 2.37 to 2.37.308 (2026H1 prior to Update 7)

Timeline

  • 2026-09-09: disclosed
  • 2026-09-09: patched: Updates available for all affected release tracks

References

Related threats