Improper Permission Check in Velociraptor Server Metadata Management
CVE-2026-78411
6.5MEDIUM
What is CVE-2026-78411?
The Velociraptor application includes a vulnerability in its SetClientMetadata function, which mishandles permission checks. This flaw allows users possessing LABEL_CLIENTS permission to modify critical server metadata. Such metadata typically contains site-wide configuration settings, which should be strictly controlled to prevent unauthorized changes. If exploited, this vulnerability could enable users to alter configurations that are traditionally reserved for server administrators, potentially leading to significant security risks for affected systems.
Affected Version(s)
Velociraptor Linux 0 < 0.77.3
