---
id: CVE-2026-81846
title: >-
  An authorization bypass in the runZero Platform MCP service has been resolved
  in version 5.1.260826.0
summary: >-
  An authorization bypass in the runZero Platform MCP service has been resolved
  in version 5.1.260826.0. This issue is an instance of CWE-639: Authorization
  Bypass Through User-Controlled Key and has an estimated CVSS score of
  CVSS:3.1/AV:…
severity: low
cvss: 3.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N'
cwe:
  - CWE-639
published: '2026-09-01'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T15:52:04.827'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81846'
references:
  - url: 'https://help.runzero.com/docs/release-notes/#512608260'
    label: 44488dab-36db-4358-99f9-bc116477f914
  - url: >-
      https://www.runzero.com/advisories/runzero-mcp-findings-summaries-data-leak-cve-2026-81846
    label: 44488dab-36db-4358-99f9-bc116477f914
tags:
  - nvd
epss: 0.00267
epssPercentile: 0.1679
ingestedAt: '2026-09-09T16:14:05.518Z'
---

## Overview

An authorization bypass in the runZero Platform MCP service has been resolved in version 5.1.260826.0. This issue is an instance of CWE-639: Authorization Bypass Through User-Controlled Key and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N (3.5 Low).

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
