Junglewise Threat Intelligence

CVE-2026-87072: Tanium Comply improper access control privilege escalation

CVE-2026-87072 · Severity: high · CVSS 7.1 · Published 2026-09-09

Technologies: Tanium Comply. Vendors: Tanium.

Executive brief

Tanium Comply, a compliance and risk management platform used by enterprises, contains an improper access control vulnerability that allows authenticated users with reporting permissions to gain unauthorized read and write access to sensitive data. An attacker with valid Comply credentials could access or modify compliance records and organizational data beyond their assigned permissions, potentially exposing sensitive business information or enabling fraudulent compliance modifications.

Technical details

The vulnerability is an improper access control flaw in Tanium Comply that allows authenticated users with the "Comply Report" permission to bypass authorization checks and access resources outside their permission scope. The vulnerability requires valid Tanium credentials (authentication required, network accessible), and affects Comply versions v2.32 through v2.32.252 (2025H1), v2.35 through v2.35.306 (2025H2), and v2.37 through v2.37.308 (2026H1). An authenticated attacker can achieve both read and write access to unauthorized data. Patches are available for all affected versions: Update 24 for 2025H1 Release, Update 14 for 2025H2 Release, and Update 7 for 2026H1 Release.

Affected products

  • Tanium Comply v2.32 to v2.32.252 (2025H1), v2.35 to v2.35.306 (2025H2), v2.37 to v2.37.308 (2026H1)

Timeline

  • 2026-09-09: disclosed
  • 2026-09-09: patched: Patches available for all affected releases

References

Related threats