VulnerabilityAnalyzed
CVE-2026-5382
An issue that could expose records outside of the authorized organization scope through the MCP endpoints has been resolved.
LOW 3.0EPSS 0.17%
Does this matter?
Lower severity and a low EPSS score (0.17%). Track it; it rarely justifies an emergency change on its own.
Description
An issue that could expose records outside of the authorized organization scope through the MCP endpoints has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N (3.0 Low). This issue was fixed in version 4.0.260206.0 of the runZero Platform.
- CVSS 3.1
- 3.0 LOWCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N
- EPSS
- 0.17% probability · 7th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- runzero/runzero platform
- Source
- 44488dab-36db-4358-99f9-bc116477f914
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.