Junglewise Threat Intelligence

CVE-2026-87075: Tanium Comply improper access control in vulnerability sources

CVE-2026-87075 · Severity: high · CVSS 8.1 · Published 2026-09-09

Technologies: Tanium Comply. Vendors: Tanium.

Executive brief

Tanium Comply is a vulnerability and compliance management platform used by enterprises to track and remediate security issues. An improper access control flaw allows authenticated users with certain permissions to delete built-in vulnerability sources from the system, potentially disrupting vulnerability management and compliance reporting capabilities.

Technical details

The vulnerability is an improper access control issue in Tanium Comply that fails to properly validate authorization before allowing deletion operations. An authenticated user with the "comply report content write" permission can delete built-in vulnerability sources from the Comply database, affecting the integrity of vulnerability data. The attack requires network access and valid authentication credentials with specific permissions; no user interaction is needed beyond the malicious API calls. Patches are available: v2.32.252 or later (2025H1), v2.35.306 or later (2025H2), and v2.37.308 or later (2026H1). No workarounds are available.

Affected products

  • Tanium Comply 2.32 to 2.32.252 (2025H1), 2.35 to 2.35.306 (2025H2), 2.37 to 2.37.308 (2026H1)

Timeline

  • 2026-09-09: disclosed

References

Related threats