Tanium Comply: 16 Vulnerabilities Including SQLi and Path Traversal Disclosed Together
Tanium Comply faces a critical security event with 16 vulnerabilities disclosed, including high-severity flaws like SQL injection and path traversal.

Key findings
- 16 vulnerabilities disclosed simultaneously in Tanium Comply on September 9, 2026.
- Flaws include improper access controls, SQL injection, path traversal, and unauthorized code execution.
- High severity vulnerabilities (up to CVSSv3 8.5) pose significant risks.
- Tanium has released patches; immediate update is recommended.
- Vulnerabilities span various components of the Comply product.
On September 9, 2026, Tanium disclosed a batch of 16 vulnerabilities affecting its Comply product. The vulnerabilities, all disclosed on the same day, span multiple severity levels, with several rated as High. These flaws primarily involve improper access controls, but also include SQL injection, path traversal, information disclosure, and unauthorized code execution. The sheer volume and variety of these vulnerabilities highlight potential systemic weaknesses within the Comply platform that require immediate attention from users.
A significant portion of the disclosed vulnerabilities, including CVE-2026-87075, CVE-2026-87073, CVE-2026-87072, CVE-2026-87048, CVE-2026-87047, CVE-2026-87046, CVE-2026-87037, CVE-2026-87033, CVE-2026-87025, and CVE-2026-87019, are categorized under improper access controls. These flaws could allow unauthorized users to gain access to sensitive information or perform actions they are not permitted to.
More critical vulnerabilities were also detailed, including SQL injection in CVE-2026-87034, which could allow attackers to manipulate database queries. Path traversal vulnerabilities were identified in CVE-2026-87030 and CVE-2026-87023, potentially enabling attackers to access files and directories outside of the intended web root. Additionally, CVE-2026-87021 presents a risk of unauthorized code execution, a severe threat that could lead to a complete system compromise. CVE-2026-87035 involves information disclosure, which could expose sensitive data to unauthorized parties.
The vulnerabilities were disclosed simultaneously, suggesting a coordinated effort to address multiple issues within the Comply product. Tanium has released patches to address these vulnerabilities. Users are strongly advised to update their Comply instances to the latest versions to mitigate these risks. The specific versions affected and patched are detailed in Tanium's security advisories.
This extensive batch of vulnerabilities underscores the importance of regular security audits and timely patching for enterprise software. Users of Tanium Comply should prioritize applying the available updates to protect their systems from potential exploitation. The simultaneous disclosure of such a large number of diverse vulnerabilities warrants a thorough review of security configurations and access controls within the Comply environment.
The immediate patching of these vulnerabilities is crucial for maintaining the integrity and security of systems relying on Tanium Comply for compliance management. Further monitoring for any exploitation attempts or related security incidents is also recommended.
The vulnerabilities disclosed are:
- CVE-2026-87075: Improper access controls
- CVE-2026-87073: Improper access controls
- CVE-2026-87072: Improper access controls
- CVE-2026-87048: Improper access controls
- CVE-2026-87047: Improper access controls
- CVE-2026-87046: Improper access controls
- CVE-2026-87037: Improper access controls
- CVE-2026-87036: Improper access controls
- CVE-2026-87035: Information disclosure
- CVE-2026-87034: SQL injection
- CVE-2026-87033: Improper access controls
- CVE-2026-87030: Path traversal
- CVE-2026-87025: Improper access controls
- CVE-2026-87023: Path traversal
- CVE-2026-87021: Unauthorized code execution
- CVE-2026-87019: Improper access controls
Tanium has released security advisories detailing the patches for these vulnerabilities. Users should consult these advisories for specific version information and remediation steps.
The simultaneous disclosure of 16 vulnerabilities in Tanium Comply, ranging from improper access controls to critical issues like SQL injection and unauthorized code execution, presents a significant security challenge for organizations relying on the product. Prompt patching and security review are essential.