CVE-2026-5380: runZero Platform cleartext secret exposure
An issue that could allow an authorized user to view the clear-text secrets for a subset of credential types and fields has been resolved. This is an instance of CWE-522: Insufficiently Protected Credentials, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N (5.3 Medium). This issue was fixed in version 4.0.260204.2 of the runZero Platform.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5380?
CVE-2026-5380 is classified with a CVSS score of 3.1, indicating a moderate severity level.
How do I fix CVE-2026-5380?
To fix CVE-2026-5380, upgrade to a version of runZero Platform that is 4.0.260204.2 or later.
What type of exposure does CVE-2026-5380 involve?
CVE-2026-5380 involves exposure of cleartext secrets for certain credential types, which could be accessed by an authorized user.
What is the affected software for CVE-2026-5380?
The affected software for CVE-2026-5380 is the runZero Platform, specifically versions prior to 4.0.260204.2.
Is CVE-2026-5380 a one-time issue or could it recur?
CVE-2026-5380 was resolved, but similar issues can reoccur if proper security measures are not continuously applied.