Improper Privilege Management in runZero Platform by runZero
CVE-2026-5373

8.1HIGH

Key Information:

Vendor

Runzero

Status
Vendor
CVE Published:
7 April 2026

What is CVE-2026-5373?

An issue in the runZero Platform allowed all-organization administrators to promote user accounts to superuser status, posing significant security risks. This vulnerability, categorized under improper privilege management, was effectively resolved in version 4.0.260202.0. Users are encouraged to update to this version to mitigate any potential unauthorized access and enhance their security posture.

Affected Version(s)

Platform 0 < 4.0.260202.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

runZero
.