Products
| Product | |
| 1 | runZero Explorer |
CVE
CVE-2026-5383Executive summary #
An issue that could allow access to Explorer groups from outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:L (4.4 Medium). This issue was fixed in version 4.0.260208.0 of the runZero Explorer.
Attacker value #
An authenticated user armed with confidential information about the target organization could exploit this vulnerability to gain access to runZero Explorers associated with the targeted organization from another organization not normally associated with those Explorers. The most likely attack from there would be to disable Explorers in the targeted organization in order to create blind spots in routine assessments.
Credit #
This issue was discovered at runZero during a routine code security review.
Timeline #
2026-02-08:Â Issue identified and fixed by the vendor
2026-04-07: Published this advisory