« Volver al listado

Runzero

Runzero Platform: vulnerabilidades y CVE

Runzero Platform tiene 14 vulnerabilidades publicadas, 14 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE14
Últimos 12 meses14
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-81846Baja (3.5)0.27%—1 sept 2026
An authorization bypass in the runZero Platform MCP service has been resolved in version 5.1.260826.0. This issue is an instance of CWE-639: Authorization Bypass Through User-Controlled Key and has an estimated CVSS…
CVE-2026-7778Media (5)0.28%—5 may 2026
An issue that could allow a dashboard configuration to be viewed from outside of the authorized organization scope has been resolved. This is an instance of CWE-269: Improper Privilege Management, and has an estimated…
CVE-2026-5384Media (5.8)0.33%—7 abr 2026
An issue that could allow a credential to be updated and used for a task from outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated…
CVE-2026-5383Media (4.4)0.28%—7 abr 2026
An issue that could allow access to Explorer groups from outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of…
CVE-2026-5382Baja (3)0.27%—7 abr 2026
An issue that could expose records outside of the authorized organization scope through the MCP endpoints has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of…
CVE-2026-5381Baja (2.2)0.27%—7 abr 2026
An issue that could expose task information outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of…
CVE-2026-5380Media (5.3)0.31%—7 abr 2026
An issue that could allow an authorized user to view the clear-text secrets for a subset of credential types and fields has been resolved. This is an instance of CWE-522: Insufficiently Protected Credentials, and has an…
CVE-2026-5379Baja (3)0.18%—7 abr 2026
An issue that allowed MCP agents to access certificate information from outside of their authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated…
CVE-2026-5378Media (6.8)0.32%—7 abr 2026
An issue that allowed administrators to create and update users outside of their authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score…
CVE-2026-5376Media (5.9)0.34%—7 abr 2026
An issue that could prevent session inactivity timeouts from triggering due to automatic page reloading has been resolved. This is an instance of CWE-613: Insufficient Control of Resources After Expiration or Release,…
CVE-2026-5375Baja (2.7)0.33%—7 abr 2026
An issue that could allow a user with access to a credential to view sensitive fields through an API response has been resolved. This is an instance of CWE-200: Exposure of Sensitive Information to an Unauthorized…
CVE-2026-5374Media (5.8)0.33%—7 abr 2026
An issue that allowed MCP agents to access remediation and asset information from outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an…
CVE-2026-5373Alta (8.4)0.40%—7 abr 2026
An issue that allowed all-organization administrators to promote accounts to superuser status has been resolved. This is an instance of CWE-269: Improper Privilege Management, and has an estimated CVSS score of…
CVE-2026-5372Media (6.4)0.34%—7 abr 2026
An issue that allowed a SQL injection attack vector related to saved queries (introduced in version 4.0.260123.0). This is an instance of CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL…

Otros productos de Runzero