CVE-2026-5373 is a privilege escalation vulnerability affecting the runZero Platform that allows organization administrators to elevate user accounts to superuser status without proper authorization controls. The vulnerability stems from improper privilege management (CWE-269) and was remediated in version 4.0.260202.0. The vulnerability carries a HIGH severity rating with a CVSS score of 8.4, indicating significant risk. The attack requires network access and high-level privileges to execute but involves minimal complexity. However, the vulnerability has a wide impact scope, affecting confidentiality and integrity of the affected system. There is currently no evidence of active exploitation in the wild. The vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog, and community attention remains minimal as indicated by its inactive status on vulnerability hot lists. The extremely low EPSS score of 0.000370000 further suggests minimal real-world exploitation likelihood at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.0.260202.0CPE matchmatch criteria | cpe:2.3:a:runzero:runzero_platform:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.