Products
| Product | |
| 1 | Platform |
CVE
CVE-2026-7778Executive summary #
An issue that could allow a dashboard configuration to be viewed from outside of the authorized organization scope has been resolved. This is an instance of CWE-269: Improper Privilege Management, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N (5.0, Medium). This issue was fixed in version v4.0.260416.0 of the runZero Platform.
Attacker value #
By inspecting another organization’s dashboard, an attacker (who is also an authorized runZero user) could learn about what that organization is most concerned about with their exposure and asset management strategies, thus helping the attacker devise more specifically targeted attacks.
Credit #
This issue was discovered at runZero during a routine code security review.
Timeline #
2026-04-14: Issue identified by the vendor
2026-04-16: Issue fixed by the vendor
2026-05-05: Published this advisory