CVE-2026-5373
8.1runZero · runZero Platform
An improper privilege management vulnerability in the runZero Platform allows authorized organization administrators to escalate their account privileges to superuser status.
Executive summary
A high-severity privilege escalation vulnerability in the runZero Platform allows organization administrators to gain unauthorized superuser access, posing a significant risk to platform integrity.
Vulnerability
This vulnerability is an instance of improper privilege management (CWE-269) where an authenticated user with organization-level administrative privileges can manipulate account permissions to achieve superuser status. The attack requires high privileges and user interaction, as indicated by the CVSS vector.
Business impact
The exploitation of this flaw could allow an attacker to obtain full control over the runZero Platform, leading to unauthorized access to sensitive network discovery data and administrative functions. Given the CVSS score of 8.1, this vulnerability represents a critical risk to organizational security posture, as it facilitates unauthorized lateral movement and potential data exfiltration within the management console.
Remediation
Immediate Action: Update the runZero Platform to version 4.0.260202.0 or later to apply the necessary security patch.
Proactive Monitoring: Review administrative access logs and audit trails for unexpected changes to user roles or the promotion of accounts to superuser status.
Compensating Controls: Restrict access to the management interface to trusted networks and ensure that only strictly necessary personnel are granted organization-level administrative permissions.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Organizations utilizing the runZero Platform must prioritize the update to version 4.0.260202.0 to mitigate the risk of unauthorized privilege escalation. While exploitation requires existing administrative access, the potential for total system compromise necessitates an immediate and thorough patching cycle to ensure the continued security of the platform.
Sources
Originally found and disclosed by runZero, per the CVE Program record.