CVE-2026-81846
runZero MCP 'Findings summaries' Data Leak
CVSS Score
3.5
EPSS Score
0.0%
EPSS Percentile
0th
An authorization bypass in the runZero Platform MCP service has been resolved in version 5.1.260826.0. This issue is an instance of CWE-639: Authorization Bypass Through User-Controlled Key and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N (3.5 Low).
| CWE | CWE-639 |
| Vendor | runzero |
| Product | platform |
| Published | Sep 1, 2026 |
| Last Updated | Sep 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for runzero platform
Be the first to know when new low vulnerabilities affecting runzero platform are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
None
Availability
None
Affected Versions
runZero / Platform
4.0.251031.0 โค 5.1.260825.0
References
Credits
runZero, Inc.