Session Timeout Bypass in RunZero Platform
CVE-2026-5376

5.9MEDIUM

Key Information:

Vendor

Runzero

Status
Vendor
CVE Published:
7 April 2026

What is CVE-2026-5376?

The RunZero Platform experienced a vulnerability that hindered the functionality of session inactivity timeouts due to automatic page reloading. This flaw is categorized under CWE-613, which signifies an insufficient control of resources after their expiration or release. The issue has significant implications for user sessions, as the failure to trigger timeouts could lead to unauthorized access or session hijacking. This vulnerability was effectively addressed in version 4.0.260203.0 of the platform.

Affected Version(s)

Platform 0 < 4.0.260203.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

runZero
.