Impact
An authorization bypass flaw in the runZero Platform MCP service permits an attacker to access and exfiltrate findings summaries that should be restricted to authorized users. The vulnerability originates from improper handling of user-supplied keys that drive data access, allowing a threat actor to read sensitive security information. As a result, confidential security findings could be exposed to unintended parties, potentially revealing the organization’s security posture and exposing internal data to external observers. The weakness is classified as CWE-639, an authorization bypass through user‐controlled input.
Affected Systems
Affected systems are deployments of the runZero Platform, specifically the MCP service. The issue is present in all versions prior to 5.1.260826.0, the release that incorporated the fix. Administrators should verify their current version and move to at least that build.
Risk and Exploitability
The CVSS score of 3.5 indicates a low overall severity, but the vulnerability does enable unauthorized access to potentially sensitive findings. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, implying no widespread or known exploit activity yet. The likely attack vector is network‑based; an attacker only needs to send crafted requests to the MCP endpoint with a user-specified key. Because the flaw requires that the user knows the relevant key, the opportunity for exploitation is limited but still possible in environments with weak key management.
OpenCVE Enrichment