Products
| Product | |
| 1 | runZero Platform |
CVE
CVE-2026-5375Executive summary #
An issue that could allow a user with access to a credential to view sensitive fields through an API response has been resolved. This is an instance of CWE-200: Exposure of Sensitive Information to an Unauthorized Actor, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N (2.7 Low). This issue was fixed in version 4.0.260203.0 of the runZero Platform.
Attacker value #
An authorized user with access to a particular integration credential could take advantage of this vulnerability to gain much more information about that saved credential than what is normally provided through the UI. If exploited, this could give the attacker valuable information about the internal workings of the target organization.
Credit #
This issue was discovered at runZero during a routine code security review.
Timeline #
2026-02-03 : Issue identified and fixed by the vendor
2026-04-07 : Published this advisory