Sceawere

Vulnerability Detail

CVE-2026-81846UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

runZero MCP Authorization Bypass

Vulnerability Metadata

Severity
Low
Score / CVSS
3.5
Creation Date
3h ago
Vendor
runZero
Product
Platform
Attack Type
CWE-639 Authorization bypass through User-Controlled key
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

An authorization bypass in the runZero Platform MCP service has been resolved in version 5.1.260826.0. This issue is an instance of CWE-639: Authorization Bypass Through User-Controlled Key and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N (3.5 Low).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.5",
  "pubDate": "2026-09-01T19:17:28.333Z",
  "pubdate": "2026-09-01T19:17:28.333Z",
  "executiveSummary": "An authorization bypass vulnerability exists within the runZero Platform MCP service, classified under CWE-639: Authorization Bypass Through User-Controlled Key.\nThis vulnerability allows a remote, authenticated low-privileged user to access resources or data to which they are not explicitly authorized by manipulating user-controlled identifiers.\nThe vulnerability is rated with a CVSS:3.1 score of 3.5 (Low), characterized by a Low impact on Confidentiality and no impact on Integrity or Availability.\nSuccessful exploitation requires the attacker to possess valid low-privileged credentials and necessitates high complexity due to the specific conditions required to trigger the authorization failure.\nThe scope is marked as Changed (S:C), indicating that the vulnerability may impact components outside the immediate security boundary of the MCP service.\nOrganizations using runZero Platform should prioritize patching to version 5.1.260826.0 to remediate the underlying access control logic flaw.",
  "technicalDetails": "The vulnerability resides within the MCP (Message Control Protocol) service component of the runZero Platform. The root cause is identified as an Improper Authorization logic flaw, specifically adhering to the CWE-639 pattern where the application relies on user-supplied input to determine resource access rights without adequate server-side validation.\nIn a standard authorization flow, the MCP service is expected to perform strict object-level authorization checks. The identified flaw manifests when the service processes requests containing user-controlled keys or identifiers. If the application fails to verify that the requesting user maintains the appropriate permissions for the specific resource requested by the key, an attacker can substitute or manipulate the key to gain unauthorized access.\nThe attack flow begins with an attacker possessing legitimate, low-level platform credentials. By intercepting or crafting requests sent to the MCP service, the attacker identifies parameters that function as keys for resource lookups. By modifying these parameters—often through enumeration or prediction of valid keys—the attacker forces the backend logic to retrieve or interact with unauthorized objects. Because the application logic fails to re-validate the user's relationship with the manipulated identifier, the request is processed as legitimate.\nThe vulnerability is constrained by high complexity (AC:H), implying that the conditions for a successful bypass may involve race conditions, specific request timing, or the need to discover valid, non-obvious resource keys through reconnaissance. Despite the low impact, the scope change (S:C) indicates that this authorization bypass could potentially be chained with other platform-specific functions, extending the attacker's reach into otherwise protected management domains.\nThis issue affects the runZero Platform prior to version 5.1.260826.0. The vulnerability requires existing authentication, meaning unauthenticated external attackers cannot directly trigger the flaw. However, within an enterprise environment, an authenticated user—or an attacker who has compromised a low-privileged account—can leverage this vector for unauthorized data exposure or administrative resource access."
}
CVE-2026-81846: runZero MCP Authorization Bypass (LOW Severity, CVSS: 3.5) - Sceawere