Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Runzero
Runzero platform |
|
| Vendors & Products |
Runzero
Runzero platform |
Tue, 01 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authorization bypass in the runZero Platform MCP service has been resolved in version 5.1.260826.0. This issue is an instance of CWE-639: Authorization Bypass Through User-Controlled Key and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N (3.5 Low). | |
| Title | runZero MCP 'Findings summaries' Data Leak | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: runZero
Published:
Updated: 2026-09-01T19:36:40.308Z
Reserved: 2026-08-27T16:11:24.858Z
Link: CVE-2026-81846
Updated: 2026-09-01T19:36:37.037Z
Status : Received
Published: 2026-09-01T19:17:28.333
Modified: 2026-09-01T20:17:24.283
Link: CVE-2026-81846
No data.
OpenCVE Enrichment
Updated: 2026-09-02T02:45:04Z
-
CWE-639
Authorization Bypass Through User-Controlled Key