Permission Misconfiguration in Velociraptor Multi-Tenant Deployments
CVE-2026-18860
8.7HIGH
What is CVE-2026-18860?
Velociraptor's multi-tenant architecture allows the creation of child organizations (orgs) that can have distinct permissions. A misconfiguration in the ORG_ADMIN permission check means that child org administrators can delete other orgs without appropriate privileges. This occurs because the system inaccurately checks permissions against the caller's current org instead of the ROOT org. As a result, an admin in a child org may elevate their capabilities to administer and potentially delete other orgs improperly, posing a significant security risk.
Affected Version(s)
Velociraptor Linux 0 < 0.77.2
