SQL Injection Vulnerability in Tanium Comply Product
CVE-2026-87034

8.3HIGH

Key Information:

Vendor

Tanium

Status
Vendor
CVE Published:
9 September 2026

What is CVE-2026-87034?

A security flaw in Tanium's Comply product has been identified as a SQL injection vulnerability. This issue allows an attacker to manipulate SQL queries, potentially leading to unauthorized access to sensitive data and compromising the integrity of the application's database. Users are urged to apply the latest security updates to mitigate the risk associated with this vulnerability.

Affected Version(s)

Comply 2.32 < 2.32.252

Comply 2.35 < 2.35.306

Comply 2.37 < 2.37.308

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.