CVE-2026-5384: runZero Platform incorrect credential scope
An issue that could allow a credential to be updated and used for a task from outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N (5.8 Medium). This issue was fixed in version 4.0.26021.0 of the runZero Platform.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5384?
CVE-2026-5384 has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:.
What issue does CVE-2026-5384 address?
CVE-2026-5384 addresses improper credential scope that allows for credential updates outside of the authorized organization scope.
How do I fix CVE-2026-5384?
To fix CVE-2026-5384, upgrade the runZero Platform to version 4.0.26021.0 or later.
Which software is affected by CVE-2026-5384?
CVE-2026-5384 affects the runZero Platform versions prior to 4.0.26021.0.
What type of vulnerability is CVE-2026-5384?
CVE-2026-5384 is categorized as CWE-863: Incorrect Authorization.