Runzero
Runzero Platform: vulnerabilidades y CVE
Runzero Platform tiene 14 vulnerabilidades publicadas, 14 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses14
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-81846 | Baja (3.5) | 0.27% | — | 1 sept 2026 | An authorization bypass in the runZero Platform MCP service has been resolved in version 5.1.260826.0. This issue is an instance of CWE-639: Authorization Bypass Through User-Controlled Key and has an estimated CVSS… |
| CVE-2026-7778 | Media (5) | 0.28% | — | 5 may 2026 | An issue that could allow a dashboard configuration to be viewed from outside of the authorized organization scope has been resolved. This is an instance of CWE-269: Improper Privilege Management, and has an estimated… |
| CVE-2026-5384 | Media (5.8) | 0.33% | — | 7 abr 2026 | An issue that could allow a credential to be updated and used for a task from outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated… |
| CVE-2026-5383 | Media (4.4) | 0.28% | — | 7 abr 2026 | An issue that could allow access to Explorer groups from outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of… |
| CVE-2026-5382 | Baja (3) | 0.27% | — | 7 abr 2026 | An issue that could expose records outside of the authorized organization scope through the MCP endpoints has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of… |
| CVE-2026-5381 | Baja (2.2) | 0.27% | — | 7 abr 2026 | An issue that could expose task information outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of… |
| CVE-2026-5380 | Media (5.3) | 0.31% | — | 7 abr 2026 | An issue that could allow an authorized user to view the clear-text secrets for a subset of credential types and fields has been resolved. This is an instance of CWE-522: Insufficiently Protected Credentials, and has an… |
| CVE-2026-5379 | Baja (3) | 0.18% | — | 7 abr 2026 | An issue that allowed MCP agents to access certificate information from outside of their authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated… |
| CVE-2026-5378 | Media (6.8) | 0.32% | — | 7 abr 2026 | An issue that allowed administrators to create and update users outside of their authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score… |
| CVE-2026-5376 | Media (5.9) | 0.34% | — | 7 abr 2026 | An issue that could prevent session inactivity timeouts from triggering due to automatic page reloading has been resolved. This is an instance of CWE-613: Insufficient Control of Resources After Expiration or Release,… |
| CVE-2026-5375 | Baja (2.7) | 0.33% | — | 7 abr 2026 | An issue that could allow a user with access to a credential to view sensitive fields through an API response has been resolved. This is an instance of CWE-200: Exposure of Sensitive Information to an Unauthorized… |
| CVE-2026-5374 | Media (5.8) | 0.33% | — | 7 abr 2026 | An issue that allowed MCP agents to access remediation and asset information from outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an… |
| CVE-2026-5373 | Alta (8.4) | 0.40% | — | 7 abr 2026 | An issue that allowed all-organization administrators to promote accounts to superuser status has been resolved. This is an instance of CWE-269: Improper Privilege Management, and has an estimated CVSS score of… |
| CVE-2026-5372 | Media (6.4) | 0.34% | — | 7 abr 2026 | An issue that allowed a SQL injection attack vector related to saved queries (introduced in version 4.0.260123.0). This is an instance of CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL… |