CVE-2026-81846

Summary

An authorization bypass in the runZero Platform MCP service has been resolved in version 5.1.260826.0. This issue is an instance of CWE-639: Authorization Bypass Through User-Controlled Key and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N (3.5 Low).

Affected Software

VendorProductVersion RangeStatus
runZeroPlatform4.0.251031.0 <= 5.1.260825.0affected

Weaknesses

  • CWE-639: CWE-639 Authorization bypass through User-Controlled key

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References