Junglewise Threat Intelligence

CVE-2026-81846: runZero Platform MCP authorization bypass

CVE-2026-81846 · Severity: low · CVSS 3.5 · Published 2026-09-01

Technologies: runZero Platform.

Executive brief

The runZero Platform's Model Context Protocol (MCP) service contains an authorization flaw that could allow authenticated users with limited privileges to access sensitive vulnerability findings summaries they should not have permission to view. This could lead to disclosure of security assessment data to unauthorized personnel within an organization.

Technical details

The vulnerability is an authorization bypass (CWE-639: Authorization Bypass Through User-Controlled Key) in the runZero Platform MCP service that allows authenticated users to access findings summaries without proper authorization checks. The flaw requires an authenticated user with low privileges and specific network conditions (high complexity attack), but no user interaction. An attacker can read sensitive vulnerability data they are not authorized to access. The issue has been patched in version 5.1.260826.0 and later.

Affected products

  • runZero Platform before 5.1.260826.0

Timeline

  • 2026-09-01: disclosed
  • 2026-09-08: patched: fix released in version 5.1.260826.0

References