PT-2026-30877 · Unknown · Runzero Platform

Runzero

·

Published

2026-04-07

·

Updated

2026-04-07

·

CVE-2026-5382

CVSS v3.1

3.0

Low

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions runZero Platform versions prior to 4.0.260206.0
Description The software contains an authorization issue that could expose records outside of the authorized organization scope through the MCP endpoints. The issue is classified as CWE-863: Incorrect Authorization.
Recommendations Update to version 4.0.260206.0 or later.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-5382

Affected Products

Runzero Platform