CVE-2026-81846: runZero MCP 'Findings summaries' Data Leak
An authorization bypass in the runZero Platform MCP service has been resolved in version 5.1.260826.0. This issue is an instance of CWE-639: Authorization Bypass Through User-Controlled Key and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N (3.5 Low).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
runZero Platform MCP serviceto a version that resolves this vulnerability.Fixed in 5.1.260826.0
Event History
Frequently Asked Questions
What level of access does an attacker need?
Exploitation requires low-level privileges and can be performed over the network without user interaction. The attack complexity is rated high.
What is the expected security impact?
The issue can result in limited disclosure of confidential information. The CVSS vector indicates no impact on integrity or availability.
Which version contains the fix?
The authorization bypass was resolved in runZero Platform MCP service version 5.1.260826.0.