Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Authorization bypass in runZero Platform MCP service

An authorization bypass vulnerability (CWE-639) was discovered in the runZero Platform MCP service, allowing users with low privileges to access resources they should not have access to. The issue has been resolved in version 5.1.260826.0.

Disclosed 1 September 2026 · Record updated 13 September 2026

Impact

Authorization bypass allowing privilege escalation to access restricted resources

Our coverage

No articles linked to this incident yet.

Sources

  1. github.comhttps://github.com/advisories/GHSA-29cr-9cjx-c8cg