SQL Injection Vulnerability in RunZero Platform
CVE-2026-5372

6.4MEDIUM

Key Information:

Vendor

Runzero

Status
Vendor
CVE Published:
7 April 2026

What is CVE-2026-5372?

A SQL injection vulnerability exists in the RunZero Platform, enabling malicious actors to manipulate saved SQL queries. This flaw, stemming from improper neutralization of special elements used in SQL commands, poses significant risks to data integrity and confidentiality. The issue was introduced in version 4.0.260123.0 and was remediated in the subsequent release, version 4.0.260123.1. Users are encouraged to update their software to mitigate potential exploitation.

Affected Version(s)

Platform 4.0.260123.0 < 4.0.260123.1

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

runZero
.