CVE-2026-5375 is an information disclosure vulnerability in the runZero Platform that allows authenticated users with credential access to view sensitive fields through API responses that should be restricted. The vulnerability stems from improper access controls on sensitive data exposed in API endpoints and has been resolved in version 4.0.260203.0. The vulnerability carries a CVSS score of 2.7 (Low) with a network attack vector requiring high-level privileges and no user interaction. While the attack has low complexity, the impact is limited to confidentiality breaches with no integrity or availability consequences, making this a low-severity issue with minimal real-world risk. Exploitation status indicates no active threats or community attention at this time. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities (KEV) catalog, exploit code is not publicly available, and the EPSS score of 0.0004 suggests minimal probability of exploitation in the wild. Organizations should prioritize patching based on normal update schedules rather than emergency response protocols.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.0.260203.0CPE matchmatch criteria | cpe:2.3:a:runzero:runzero_platform:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.