SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2026-5382

An issue that could expose records outside of the authorized organization scope through the MCP endpoints has been resolved.

LOW 3.0EPSS 0.17%

Does this matter?

Lower severity and a low EPSS score (0.17%). Track it; it rarely justifies an emergency change on its own.

Description

An issue that could expose records outside of the authorized organization scope through the MCP endpoints has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N (3.0 Low). This issue was fixed in version 4.0.260206.0 of the runZero Platform.

CVSS 3.1
3.0 LOWCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N
EPSS
0.17% probability · 7th percentile
CISA KEV
Not listed
Weakness
CWE-863
Affected
runzero/runzero platform
Source
44488dab-36db-4358-99f9-bc116477f914

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.