{"id":"CVE-2026-81846","title":"An authorization bypass in the runZero Platform MCP service has been resolved in version 5.1.260826.0","summary":"An authorization bypass in the runZero Platform MCP service has been resolved in version 5.1.260826.0. This issue is an instance of CWE-639: Authorization Bypass Through User-Controlled Key and has an estimated CVSS score of CVSS:3.1/AV:…","severity":"low","cvss":3.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N","cwe":["CWE-639"],"published":"2026-09-01","updated":"2026-09-09","sourceUpdated":"2026-09-09T15:52:04.827","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-81846","references":[{"url":"https://help.runzero.com/docs/release-notes/#512608260","label":"44488dab-36db-4358-99f9-bc116477f914"},{"url":"https://www.runzero.com/advisories/runzero-mcp-findings-summaries-data-leak-cve-2026-81846","label":"44488dab-36db-4358-99f9-bc116477f914"}],"tags":["nvd"],"epss":0.00206,"epssPercentile":0.11038,"ingestedAt":"2026-09-09T16:14:05.518Z","slug":"CVE-2026-81846","body":"## Overview\n\nAn authorization bypass in the runZero Platform MCP service has been resolved in version 5.1.260826.0. This issue is an instance of CWE-639: Authorization Bypass Through User-Controlled Key and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N (3.5 Low).\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":19,"depthScoreParts":{"impact":19.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}