CVE-2026-5374
Incorrect Authorization in runZero MCP Agents Allows Data Exposure
Publication date: 2026-04-07
Last updated on: 2026-04-21
Assigner: 44488dab-36db-4358-99f9-bc116477f914
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| runzero | runzero_platform | to 4.0.260202.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-863 | The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. |
Attack-Flow Graph
AI Powered Q&A
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
The vulnerability allowed MCP agents to access remediation and asset information beyond their authorized organizational scope, leading to a high confidentiality impact. Such unauthorized access to sensitive information could potentially result in non-compliance with data protection regulations like GDPR and HIPAA, which mandate strict controls on access to sensitive and personal data.
By exposing sensitive organizational information, this issue could increase the risk of data breaches or unauthorized data exposure, which are critical concerns under these regulations. Therefore, addressing this vulnerability is important to maintain compliance with standards that require proper authorization and protection of sensitive data.
Can you explain this vulnerability to me?
The CVE-2026-5374 vulnerability is an information leak issue in the runZero Platform MCP (Managed Control Plane) agents. It allowed these agents to access remediation and asset information beyond their authorized organizational scope, which means they could see data they were not supposed to access. This is classified as CWE-863: Incorrect Authorization.
The vulnerability has a CVSS 3.1 base score of 5.8 (Medium), indicating it can be exploited over the network but requires high privileges and has a high attack complexity. It impacts confidentiality by exposing sensitive information but does not affect integrity or availability.
How can this vulnerability impact me? :
If exploited, this vulnerability could allow an attacker to obtain sensitive remediation and asset information from outside their authorized organizational scope. This exposure of sensitive information could be used to tailor further attacks against the targeted organization.
What immediate steps should I take to mitigate this vulnerability?
To mitigate the CVE-2026-5374 vulnerability, you should update the runZero Platform to version 4.0.260202.0 or later, where the issue has been fixed.
This update addresses the incorrect authorization issue that allowed MCP agents to access remediation and asset information outside their authorized organizational scope.