Description
An authorization bypass in the runZero Platform MCP service has been resolved in version 5.1.260826.0. This issue is an instance of CWE-639: Authorization Bypass Through User-Controlled Key and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N (3.5 Low).
Published: 2026-09-01
Score: 3.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass
Action: Patch
AI Analysis

Impact

An authorization bypass flaw in the runZero Platform MCP service permits an attacker to access and exfiltrate findings summaries that should be restricted to authorized users. The vulnerability originates from improper handling of user-supplied keys that drive data access, allowing a threat actor to read sensitive security information. As a result, confidential security findings could be exposed to unintended parties, potentially revealing the organization’s security posture and exposing internal data to external observers. The weakness is classified as CWE-639, an authorization bypass through user‐controlled input.

Affected Systems

Affected systems are deployments of the runZero Platform, specifically the MCP service. The issue is present in all versions prior to 5.1.260826.0, the release that incorporated the fix. Administrators should verify their current version and move to at least that build.

Risk and Exploitability

The CVSS score of 3.5 indicates a low overall severity, but the vulnerability does enable unauthorized access to potentially sensitive findings. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, implying no widespread or known exploit activity yet. The likely attack vector is network‑based; an attacker only needs to send crafted requests to the MCP endpoint with a user-specified key. Because the flaw requires that the user knows the relevant key, the opportunity for exploitation is limited but still possible in environments with weak key management.

Generated by OpenCVE AI on September 2, 2026 at 02:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the runZero Platform MCP service to version 5.1.260826.0 or later to apply the authorization bypass fix.
  • Configure least‑privilege access controls for the MCP service so that only users with clear permissions can request findings summaries.
  • Audit current key management practices to ensure that user-controlled keys are not exposed or shared in an insecure manner.

Generated by OpenCVE AI on September 2, 2026 at 02:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Runzero
Runzero platform
Vendors & Products Runzero
Runzero platform

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description An authorization bypass in the runZero Platform MCP service has been resolved in version 5.1.260826.0. This issue is an instance of CWE-639: Authorization Bypass Through User-Controlled Key and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N (3.5 Low).
Title runZero MCP 'Findings summaries' Data Leak
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Runzero Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: runZero

Published:

Updated: 2026-09-01T19:36:40.308Z

Reserved: 2026-08-27T16:11:24.858Z

Link: CVE-2026-81846

cve-icon Vulnrichment

Updated: 2026-09-01T19:36:37.037Z

cve-icon NVD

Status : Deferred

Published: 2026-09-01T19:17:28.333

Modified: 2026-09-09T15:52:04.827

Link: CVE-2026-81846

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T02:45:04Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key