PT-2026-84399 · Runzero · Runzero Platform Mcp Service
CVSS v3.1
3.5
Low
| Vector | AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
runZero Platform MCP service versions prior to 5.1.260826.0
Description
An authorization bypass exists in the MCP service. This issue is an instance of Authorization Bypass Through User-Controlled Key, which occurs when an application uses a user-supplied input to access a resource without properly verifying if the user is authorized to access that specific resource.
Recommendations
Update to version 5.1.260826.0.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Runzero Platform Mcp Service