CVE-2026-5379 LOW

CVE-2026-5379: runZero Platform MCP certification information leak

Vendor Runzero
Product Platform
Weakness CWE-863 · Incorrect authorization
Published April 7, 2026
Last update April 7, 2026

CVSS base score

3.0/10
Attack vector Network
Attack complexity High
Privileges required High
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N

What the vulnerability does

01Description

An issue that allowed MCP agents to access certificate information from outside of their authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N (3.0 Low). This issue was fixed in version 4.0.260203.0 of the runZero Platform.

Key dates

02Disclosure timeline

April 7, 2026 CVE published
April 7, 2026 Record updated