Authorization bypass in runZero Platform MCP service
An authorization bypass vulnerability (CWE-639) was discovered in the runZero Platform MCP service, allowing users with low privileges to access resources they should not have access to. The issue has been resolved in version 5.1.260826.0.
Disclosed 1 September 2026 · Record updated 13 September 2026
Impact
Authorization bypass allowing privilege escalation to access restricted resources
Our coverage
No articles linked to this incident yet.
Sources
- github.comhttps://github.com/advisories/GHSA-29cr-9cjx-c8cg
