SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2026-5374

An issue that allowed MCP agents to access remediation and asset information from outside of the authorized organization scope has been resolved.

MEDIUM 5.8EPSS 0.21%

Does this matter?

Lower severity and a low EPSS score (0.21%). Track it; it rarely justifies an emergency change on its own.

Description

An issue that allowed MCP agents to access remediation and asset information from outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N (5.8 Medium). This issue was fixed in version 4.0.260202.0 of the runZero Platform.

CVSS 3.1
5.8 MEDIUMCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
EPSS
0.21% probability · 11th percentile
CISA KEV
Not listed
Weakness
CWE-863
Affected
runzero/runzero platform
Source
44488dab-36db-4358-99f9-bc116477f914

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.