Products
| Product | |
| 1 | runZero Platform |
CVE
CVE-2026-5379Executive summary #
An issue that allowed MCP agents to access certificate information from outside of their authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N (3.0 Low). This issue was fixed in version 4.0.260203.0 of the runZero Platform.
Attacker value #
By leveraging the MCP API, authorized users could learn some details about certificates issued and used in organizations they could not otherwise access. This can, in turn, help inform an attacker about specific details of the targeted organization in order to further another attack.
Credit #
This issue was discovered at runZero during a routine code security review.
Timeline #
2026-02-03 : Issue identified and fixed by the vendor
2026-04-07 : Published this advisory