ZeroHour

CVE-2026-5374

CVSS 3.1
5.8 medium
EPSS
<1%p11
Published
()
Modified
Description

An issue that allowed MCP agents to access remediation and asset information from outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N (5.8 Medium). This issue was fixed in version 4.0.260202.0 of the runZero Platform.

Vendors
runzero
Products
runzero platform
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.