Path Traversal Vulnerability in Tanium Comply Product
CVE-2026-87023

8.5HIGH

Key Information:

Vendor

Tanium

Status
Vendor
CVE Published:
9 September 2026

What is CVE-2026-87023?

Tanium has addressed a path traversal vulnerability in its Comply product that could allow attackers to access sensitive files and directories beyond the intended scope. This flaw can be exploited if proper validation and sanitization of input data are not enforced. Users of Tanium Comply should promptly apply available patches to mitigate the risk associated with this vulnerability and protect their systems from potential breaches.

Affected Version(s)

Comply 2.32 < 2.32.252

Comply 2.35 < 2.35.306

Comply 2.37 < 2.37.308

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.