Permission Misconfiguration in Velociraptor Multi-Tenant Deployments
CVE-2026-18860

8.7HIGH

Key Information:

Vendor

Rapid7

Vendor
CVE Published:
11 August 2026

What is CVE-2026-18860?

Velociraptor's multi-tenant architecture allows the creation of child organizations (orgs) that can have distinct permissions. A misconfiguration in the ORG_ADMIN permission check means that child org administrators can delete other orgs without appropriate privileges. This occurs because the system inaccurately checks permissions against the caller's current org instead of the ROOT org. As a result, an admin in a child org may elevate their capabilities to administer and potentially delete other orgs improperly, posing a significant security risk.

Affected Version(s)

Velociraptor Linux 0 < 0.77.2

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Hamad Alghamdi
.