CVE-2026-7778: runZero Platform dashboard configuration exposure
An issue that could allow a dashboard configuration to be viewed from outside of the authorized organization scope has been resolved. This is an instance of CWE-269: Improper Privilege Management, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N (5.0, Medium). This issue was fixed in version v4.0.260416.0 of the runZero Platform.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
runZero Platformto a version that resolves this vulnerability.Fixed in v4.0.260416.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7778?
CVE-2026-7778 has an estimated CVSS score indicating a moderate severity level.
How do I fix CVE-2026-7778?
To fix CVE-2026-7778, upgrade the runZero Platform to version 4.0.260416.0 or later.
What kind of vulnerability is CVE-2026-7778?
CVE-2026-7778 is identified as CWE-269, which relates to improper privilege management.
Who is affected by CVE-2026-7778?
CVE-2026-7778 affects users of the runZero Platform versions prior to 4.0.260416.0.
What are the potential risks associated with CVE-2026-7778?
The potential risks include unauthorized access to dashboard configuration data outside authorized organizational scopes.