CVE-2026-5382 is an authorization bypass vulnerability in the runZero Platform that could allow authenticated users to access records outside their authorized organization scope through the MCP endpoints. The issue stems from improper access controls (CWE-863) and was remediated in platform version 4.0.260206.0. This vulnerability specifically affects the runZero Platform prior to the patched version. The vulnerability carries a CVSS score of 3.0 (Low severity) with a network attack vector requiring high privilege level access and high attack complexity. The impact is limited to low-level confidentiality compromise, with no integrity or availability impact. The attack requires an authenticated high-privileged user to exploit the flaw through network-based MCP endpoints. There is no evidence of active exploitation in the wild, as CVE-2026-5382 does not appear on the CISA Known Exploited Vulnerabilities (KEV) list and is currently inactive on vulnerability hot lists. The EPSS score of 0.00039 indicates minimal probability of exploitation relative to other CVEs. Organizations running runZero Platform should upgrade to version 4.0.260206.0 or later as a standard security practice, though immediate emergency action is not warranted given the low severity rating and lack of exploitation activity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.0.260206.0CPE matchmatch criteria | cpe:2.3:a:runzero:runzero_platform:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.