CVE-2026-87025
Tanium addressed an improper access controls vulnerability in Comply.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.4
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
- EPSS probability
- 0.17%
- CWE
- CWE-639
- Published
- 2026-09-09
- Last modified
- 2026-09-09
Affected products
- Tanium Comply
- Tanium Comply
- Tanium Comply
Weakness type
Related vulnerabilities
- CVE-2026-47156 — MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator
- CVE-2026-67403 — Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API....
- CVE-2026-86763 — snipe-it 7.0.12 through 8.6.3 Authorization Bypass via Importer
- CVE-2026-86761 — snipe-it 8.6.3 before 8.7.0 Authorization Bypass via print endpoints
- CVE-2026-86743 — Snipe-IT before 8.7.0 Authorization Bypass via Asset Acceptance Report
- CVE-2026-87809 — Siyuan before v3.8.2 Information Disclosure via Export Preview
- CVE-2026-87033 — Tanium addressed an improper access controls vulnerability in Comply.
- CVE-2026-87047 — Tanium addressed an improper access controls vulnerability in Comply.