CVE-2026-5373: runZero Platform superuser privilege escalation
Published Apr 7, 2026
·Updated
An issue that allowed all-organization administrators to promote accounts to superuser status has been resolved. This is an instance of CWE-269: Improper Privilege Management, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N (8.1 High). This issue was fixed in version 4.0.260202.0 of the runZero Platform.
Affected Software
2 affected components
runZero runZero Platform<4.0.260202.0
runZero runZero Platform<4.0.260202.0
Remediation
Information
This issue was fixed in version 4.0.260202.0 of the runZero Platform
Event History
Apr 7, 2026
CVE Published
via MITRE·02:10 PM
Data Sourced
via MITRE·02:10 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeaknessAffected Software
Aug 24, 58276
Event
via FIRST·10:12 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-5373?
CVE-2026-5373 has a high severity rating of 8.4.
2
How do I fix CVE-2026-5373?
To fix CVE-2026-5373, update the runZero Platform to version 4.0.260202.0 or later.
3
What is the risk associated with CVE-2026-5373?
The risk associated with CVE-2026-5373 is classified as medium with an EPSS score of 0.00037.
4
What vulnerability type does CVE-2026-5373 fall under?
CVE-2026-5373 falls under CWE-269: Improper Privilege Management.
5
Who is affected by CVE-2026-5373?
CVE-2026-5373 affects all-organization administrators of the runZero Platform.