Incorrect Authorization Vulnerability in runZero Platform by runZero
CVE-2026-5378

5.8MEDIUM

Key Information:

Vendor

Runzero

Status
Vendor
CVE Published:
7 April 2026

What is CVE-2026-5378?

A vulnerability in the runZero Platform allowed administrators to create and update user accounts beyond their authorized organizational limits, posing a risk of unauthorized access. This flaw falls under the category of Incorrect Authorization, impacting user permissions and potentially compromising sensitive information. The issue has been addressed in version 4.0.260203.0 and highlights the importance of secure user management within systems.

Affected Version(s)

Platform 0 < 4.0.260203.0

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

runZero
.