CVE-2026-5382: runZero Platform MCP endpoint information leak
An issue that could expose records outside of the authorized organization scope through the MCP endpoints has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N (3.0 Low). This issue was fixed in version 4.0.260206.0 of the runZero Platform.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5382?
CVE-2026-5382 has an estimated CVSS score indicating a high severity due to the incorrect authorization leading to potential information exposure.
How do I fix CVE-2026-5382?
To fix CVE-2026-5382, upgrade your runZero Platform to version 4.0.260206.0 or later to address the endpoint information leak.
What software is affected by CVE-2026-5382?
CVE-2026-5382 affects the runZero Platform versions up to 4.0.260206.0.
What type of vulnerability is CVE-2026-5382?
CVE-2026-5382 is categorized as CWE-863: Incorrect Authorization, which may lead to unauthorized data exposure.
What are the potential risks of CVE-2026-5382?
The risks associated with CVE-2026-5382 include unauthorized access to sensitive records outside of the authorized organization scope.