An issue that could allow access to Explorer groups from outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:L (4.4 Medium). This issue was fixed in version 4.0.260208.0 of the runZero Explorer.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
This issue was fixed in version 4.0.26021.0 of the runZero Explorer
Workaround
No workaround given by the vendor.
References
History
Tue, 07 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue that could allow access to Explorer groups from outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:L (4.4 Medium). This issue was fixed in version 4.0.260208.0 of the runZero Explorer. | |
| Title | runZero Explorer missing authorization check | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: runZero
Published:
Updated: 2026-04-07T20:00:12.927Z
Reserved: 2026-04-01T20:20:41.608Z
Link: CVE-2026-5383
No data.
Status : Received
Published: 2026-04-07T15:17:48.543
Modified: 2026-04-07T15:17:48.543
Link: CVE-2026-5383
No data.
OpenCVE Enrichment
No data.
Weaknesses