Session Timeout Bypass in RunZero Platform
CVE-2026-5376
5.9MEDIUM
What is CVE-2026-5376?
The RunZero Platform experienced a vulnerability that hindered the functionality of session inactivity timeouts due to automatic page reloading. This flaw is categorized under CWE-613, which signifies an insufficient control of resources after their expiration or release. The issue has significant implications for user sessions, as the failure to trigger timeouts could lead to unauthorized access or session hijacking. This vulnerability was effectively addressed in version 4.0.260203.0 of the platform.
Affected Version(s)
Platform 0 < 4.0.260203.0
