Improper Permission Check in Velociraptor Server Metadata Management
CVE-2026-78411

6.5MEDIUM

Key Information:

Vendor

Rapid7

Vendor
CVE Published:
5 October 2026

What is CVE-2026-78411?

The Velociraptor application includes a vulnerability in its SetClientMetadata function, which mishandles permission checks. This flaw allows users possessing LABEL_CLIENTS permission to modify critical server metadata. Such metadata typically contains site-wide configuration settings, which should be strictly controlled to prevent unauthorized changes. If exploited, this vulnerability could enable users to alter configurations that are traditionally reserved for server administrators, potentially leading to significant security risks for affected systems.

Affected Version(s)

Velociraptor Linux 0 < 0.77.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yuval Miller
Leon Kayaliev
.