CVE-2026-87030: Tanium addressed a path traversal vulnerability in Comply.
Published Sep 9, 2026
·Updated
Tanium addressed a path traversal vulnerability in Comply.
Affected Software
1 affected component
Tanium Comply
Event History
Sep 9, 2026
CVE Published
via MITRE·02:07 AM
Data Sourced
via MITRE·02:07 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is realistically exposed to exploitation?
Network-accessible Tanium Comply deployments are exposed if an attacker has low-level privileges. The attack requires no user interaction and has low attack complexity.
2
What impact could successful exploitation have?
The CVSS vector indicates high integrity impact and low availability impact, with no confidentiality impact. It also indicates a changed scope, meaning effects may extend beyond the initially vulnerable security authority.