Skip to content
Please update to the latest release 0.77.3 to address Multiple CVEs.

CVE-2026-78411: Velociraptor Server Metadata update with Insufficient Permission Check

Published on 2026-07-31 Vulnogram
Description

Velociraptor's SetClientMetadata used the wrong permission check to enforce setting metadata on the server. This allows a user with LABEL_CLIENTS permission to update the server metadata.


Server metadata is often used to store site wide configuration data that should only be updated by the server admin.

Problem CWE-863: Incorrect Authorization
Required configuration for exposure This can only be exploited by an authenticated user with the "investigator" role.  The usual audit logging will record misuse.
ProductAffected
Rapid7 Velociraptor on Linux
source repo
Default status is unaffected
before 0.77.3
Credits
  • Yuval Miller and Leon Kayaliev