SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-81846

LOW · CVSS 3.5 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The runZero Platform MCP service is vulnerable to an authorization bypass, allowing unauthorized access due to user-controlled keys. Although the CVSS score is low, organizations using this platform should prioritize updating to version 5.1.260826.0 to mitigate potential security risks. This issue primarily affects users who rely on the MCP service for managing their network assets.

CVE
CVE-2026-81846
Severity
LOW
CVSS
3.5
EPSS
0.21%

Original NVD Description

An authorization bypass in the runZero Platform MCP service has been resolved in version 5.1.260826.0. This issue is an instance of CWE-639: Authorization Bypass Through User-Controlled Key and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N (3.5 Low).