Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2931 articles · 104969 vulns · 36/41 feeds (7d)
← Back to list
5.3
CVE-2026-5380PATCHED
runzero · platform

runZero Platform cleartext secret exposure

Description

An issue that could allow an authorized user to view the clear-text secrets for a subset of credential types and fields has been resolved. This is an instance of CWE-522: Insufficiently Protected Credentials, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N (5.3 Medium). This issue was fixed in version 4.0.260204.2 of the runZero Platform.

Affected Products

VendorProductVersions
runzeroplatform0, 3.0, 5.2

References

  • https://help.runzero.com/docs/release-notes/#402602042(release-notes)
  • https://www.runzero.com/advisories/runzero-platform-cleartext-exposure-cve-2026-5380/(vendor-advisory)

Related News (1 articles)

Tier C
VulDB4h ago
CVE-2026-5380 | runZero Platform up to 3.0/5.2 authorization
→ No new info (linked only)
CVSS 3.15.3 HIGH
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
4.0.260204.2
CWECWE-863, CWE-284
PublishedApr 7, 2026
Last enriched3h agov2
Tags
CVE-2026-5380
Trending Score27
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-5383
runZero Explorer missing authorization check
Trending: 27
HIGHCVE-2026-5378
runZero Platform user creation leak
Trending: 27
MEDIUMCVE-2026-5376
runZero Platform session timeout failure
Trending: 27
MEDIUMCVE-2026-5384
runZero Platform incorrect credential scope
Trending: 23
MEDIUMCVE-2026-5382
runZero Platform MCP endpoint information leak
Trending: 23

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 7, 2026
Discovered by ZDM
Apr 7, 2026
Patch Available
Apr 7, 2026
Updated: affectedVersions, severity, cweIds, tags
Apr 7, 2026

Version History

v2
Last enriched 3h ago
v2Tier C3h ago

Updated affected versions to include 3.0 and 5.2, changed severity to HIGH, added new CWE-284, and included CVE-2026-5380 tag.

affectedVersionsseveritycweIdstags
via VulDB
v15h ago

Initial creation