Description
An issue that allowed administrators to create and update users outside of their authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N (5.8 Medium). This issue was fixed in version 4.0.260203.0 of the runZero Platform.
Published: 2026-04-07
Score: 5.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized User Creation and Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

An issue in the runZero Platform permitted administrators to create or modify users beyond their authorized organization scope. This vulnerable behavior enabled the creation of new accounts or the alteration of existing ones without appropriate authorization checks, potentially granting attackers or rogue administrators access to sensitive data within other organizations. The flaw is identified as CWE‑863, representing Incorrect Authorization. The estimated CVSS score of 5.8 indicates a medium severity effect; the vulnerability does not compromise confidentiality or availability directly but can elevate the attacker’s privileges to a level that may expose internal resources.

Affected Systems

The vulnerability applies to the runZero Platform, specifically affecting instances that rely on its user management module. The issue exists in all versions prior to 4.0.260203.0 and was explicitly fixed in that release. Users of earlier Platform versions are at risk unless they upgrade the software.

Risk and Exploitability

The medium CVSS score reflects the need for administrative access to exploit the flaw. No publicly available exploit details are documented, and the EPSS score is not provided. Since the vulnerability is not listed in the CISA KEV catalog, there is no known large‑scale exploitation record. Nevertheless, the attack may be carried out by any user with existing administrative privileges who can exploit the authorization bypass to create or update users outside their designated scope. The impact is limited to the compromise of isolation boundaries between organizational accounts rather than system control or data breach.

Generated by OpenCVE AI on April 7, 2026 at 20:09 UTC.

Remediation

Vendor Solution

This issue was fixed in version 4.0.260203.0 of the runZero Platform


OpenCVE Recommended Actions

  • Update the runZero Platform to version 4.0.260203.0 or later to apply the official fix.
  • Verify existing users for unauthorized accounts or roles before applying the patch.
  • Restrict the use of administrative privileges to trusted personnel until the patch is deployed.
  • Monitor user management activity logs for any anomalous account creation or modification events.

Generated by OpenCVE AI on April 7, 2026 at 20:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Runzero
Runzero platform
Vendors & Products Runzero
Runzero platform

Tue, 07 Apr 2026 15:15:00 +0000

Type Values Removed Values Added
Description An issue that allowed administrators to create and update users outside of their authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N (5.8 Medium). This issue was fixed in version 4.0.260203.0 of the runZero Platform.
Title runZero Platform user creation leak
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Runzero Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: runZero

Published:

Updated: 2026-04-07T15:07:27.321Z

Reserved: 2026-04-01T20:13:06.790Z

Link: CVE-2026-5378

cve-icon Vulnrichment

Updated: 2026-04-07T15:07:21.912Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-07T15:17:47.763

Modified: 2026-04-08T21:27:00.663

Link: CVE-2026-5378

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-08T19:49:15Z

Weaknesses