runZero Platform taks information leak

|
Updated
Vendors runZero
Products
runZero Platform
  • runZero Platform
Related

Executive summary #

An issue that could expose task information outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N (2.2 Low). This issue was fixed in version 4.0.260205.0 of the runZero Platform.

Attacker value #

An authorized runZero user could leak information from a limited number of task types from a targeted organization they would not normally have access to. This information could give the attacker some extra insight into the kinds of tasks running in that targeted organization, and some of the data associated with those tasks, which could, in turn, help inform the attacker on tactics that are more likely to be successful.

Credit #

This issue was discovered at runZero during a routine code security review.

Timeline #

2026-02-05 : Issue identified and fixed by the vendor

2026-04-07 : Published this advisory

Written by todb

Tod Beardsley is VP of Security Research at runZero, where he "kicks assets and fakes frames." Prior to 2025, he was the Section Chief for the Vulnerability Response section for CSD/VM/VRC at CISA, the Cybersecurity and Infrastructure Security Agency, part of the US government, and a seasonal Travis County Election Judge in Texas. He's also a founder and CNA point of contact for AHA!. Tod spends much of his time involved in vulnerability research and coordinated vulnerability disclosure (CVD). He has over 30 years of hands-on security experience, stretching from in-band telephony switching to modern ICS/OT implementations. He has held IT ops, security, software engineering, and management positions in large organizations such as the US Government, Rapid7, 3Com, Dell, and Westinghouse, as both an offensive and defensive practitioner. Tod is a CVE Board member, has authored several research papers, and is an internationally-tolerated horror fiction expert.

More about todb
Subscribe Now

Get the latest news and expert insights delivered in your inbox.

Welcome to the club! Your subscription to our newsletter is successful.