Products
| Product | |
| 1 | runZero Platform |
CVE
CVE-2026-5382Executive summary #
An issue that could expose records outside of the authorized organization scope through the MCP endpoints has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N (3.0 Low). This issue was fixed in version 4.0.260206.0 of the runZero Platform.
Attacker value #
By querying specific records via the MCP endpoint provided by the product, an authorized user could exfiltrate confidential information for assets belonging to an organization they would otherwise not have access to view. This could, in turn, be used to craft more targeted attacks against that organization. Note that the attacker would not likely have precise control over which records are exposed.
Credit #
This issue was discovered at runZero during a routine code security review.
Timeline #
2026-02-06: Issue identified and fixed by the vendor
2026-04-07 : Published this advisory