Junglewise Threat Intelligence

CVE-2026-87048: Tanium Comply improper access controls vulnerability

CVE-2026-87048 · Severity: medium · CVSS 5.4 · Published 2026-09-09

Technologies: Tanium Comply. Vendors: Tanium.

Executive brief

Tanium Comply is a compliance and security scanning tool used to assess endpoint vulnerabilities across enterprise networks. An authenticated user with specific reporting and scanning permissions could exploit an access control flaw to execute security scans against endpoints they are not authorized to manage, potentially exposing sensitive systems or gathering unauthorized information.

Technical details

The vulnerability is an improper access controls flaw in Tanium Comply that fails to properly validate authorization boundaries for scan execution. An authenticated attacker with the "Comply Report Write" and "Comply Scan Execute" permissions can execute scans against endpoints beyond their assigned management scope. The attack requires valid Tanium credentials and the specific permissions noted, but no user interaction. Exploitation allows unauthorized scanning of systems the attacker lacks management rights over. Patches are available for all supported release branches: v2.32.252+, v2.35.306+, and v2.37.308+.

Affected products

  • Tanium Comply 2.32 to 2.32.252, 2.35 to 2.35.306, 2.37 to 2.37.308

Timeline

  • 2026-09-09: disclosed

References

Related threats