CVE-2026-87030
Tanium addressed a path traversal vulnerability in Comply.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L
- EPSS probability
- 0.28%
- CWE
- CWE-22
- Published
- 2026-09-09
- Last modified
- 2026-09-09
Affected products
- Tanium Comply
- Tanium Comply
- Tanium Comply
Weakness type
Related vulnerabilities
- CVE-2026-88790 — proma-ai Proma File Preview Service file-preview-service.ts resolveTargetPath path traversal
- CVE-2026-64838 — ICEcoder through 8.1 Path Traversal via oldFileName Parameter
- CVE-2026-64836 — ICEcoder through 8.1 Path Traversal via Ineffective File::check() Confinement
- CVE-2026-9166 — LFI in GIS Informatics' GisLab Laboratory Management System
- CVE-2026-78085 — Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4
- CVE-2026-15019 — Direct Download for WooCommerce <= 1.19 - Unauthenticated Arbitrary File Read via 'file_id' Path Segment
- CVE-2026-18386 — WP BackItUp Community Edition <= 2.1.0 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'backup_file' Parameter
- CVE-2026-88069 — Path traversal in Pandora archive extractor allows arbitrary file writes outside the extraction directory in pandora analysis