Products
| Product | |
| 1 | runZero Platform |
CVE
CVE-2026-81846Executive summary #
An authorization bypass in the runZero Platform MCP service has been resolved in version 5.1.260826.0. This issue is an instance of CWE-639: Authorization Bypass Through User-Controlled Key and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N (3.5 Low).
Attacker value #
An authenticated attacker who knew the UUID of a target organization could exploit this vulnerability to retrieve Findings summaries belonging to that organization, potentially revealing summary information about security issues outside of the attacker's authorized scope. No modification of data or service disruption was possible through the affected behavior.
Credit #
This issue was discovered at runZero during a routine code security review.
Timeline #
2026-08-27 : Issue identified and fixed by the vendor
2026-09-01 : Published this advisory and CVE-2026-81846