Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Runzero Platform MEDIUM 5.8
CVE-2026-5384

An issue that could allow a credential to be updated and used for a task from outside of the authorized organization scope has been resolved. This is…

Fix: 4.0.26021.0+
Fix from $1,600 2026-04-07
Runzero Platform MEDIUM 5.3
CVE-2026-5380

An issue that could allow an authorized user to view the clear-text secrets for a subset of credential types and fields has been resolved. This is an…

Fix: 4.0.260204.2+
Fix from $1,600 2026-04-07
Runzero Platform HIGH 8.4
CVE-2026-5373

An issue that allowed all-organization administrators to promote accounts to superuser status has been resolved. This is an instance of CWE-269: Impr…

Fix: 4.0.260202.0+
Fix from $1,950 2026-04-07
Runzero Platform MEDIUM 6.8
CVE-2026-5378

An issue that allowed administrators to create and update users outside of their authorized organization scope has been resolved. This is an instance…

Fix: 4.0.260203.0+
Fix from $1,600 2026-04-07
Runzero Platform MEDIUM 5.9
CVE-2026-5376

An issue that could prevent session inactivity timeouts from triggering due to automatic page reloading has been resolved. This is an instance of CWE…

Fix: 4.0.260203.0+
Fix from $1,600 2026-04-07
Runzero Platform MEDIUM 5.8
CVE-2026-5374

An issue that allowed MCP agents to access remediation and asset information from outside of the authorized organization scope has been resolved. Thi…

Fix: 4.0.260202.0+
Fix from $1,600 2026-04-07
Runzero Platform MEDIUM 6.4
CVE-2026-5372

An issue that allowed a SQL injection attack vector related to saved queries (introduced in version 4.0.260123.0). This is an instance of CWE-89: Imp…

Mitigation only
Fix from $1,600 2026-04-07