Authorization Flaw in RunZero MCP Agents
CVE-2026-5374

5.8MEDIUM

Key Information:

Vendor

Runzero

Status
Vendor
CVE Published:
7 April 2026

What is CVE-2026-5374?

A security issue was identified in the RunZero platform, where MCP agents were able to access sensitive remediation and asset information beyond their authorized organization scope. This presented a risk of unauthorized data exposure, categorized under CWE-863: Incorrect Authorization. The vulnerability has been addressed in version 4.0.260202.0 of the RunZero Platform, ensuring that access controls are properly enforced.

Affected Version(s)

Platform 0 < 4.0.260202.0

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

runZero
.