CVE-2026-7778 PUBLISHED

runZero Platform dashboard configuration exposure

Assigner: runZero
Reserved: 04.05.2026 Published: 05.05.2026 Updated: 05.05.2026

An issue that could allow a dashboard configuration to be viewed from outside of the authorized organization scope has been resolved. This is an instance of CWE-269: Improper Privilege Management, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N (5.0, Medium). This issue was fixed in version v4.0.260416.0 of the runZero Platform.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
CVSS Score: 5

Product Status

Vendor runZero
Product Platform
Versions Default: unaffected
  • affected from 0 to 4.0.260416.0 (excl.)

Credits

  • runZero finder
  • Tod Beardsley of runZero coordinator

References

Problem Types

  • CWE-269 Improper Privilege Management CWE