CVE-2026-78411: Velociraptor Server Metadata update with Insufficient Permission Check
Published on 2026-07-31
Vulnogram
CVSS · MEDIUM · 6.5 ⁄10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Scoring scenario:
GENERAL
attackVector:
NETWORK
attackComplexity:
LOW
privilegesRequired:
LOW
userInteraction:
NONE
scope:
UNCHANGED
confidentialityImpact:
NONE
integrityImpact:
HIGH
availabilityImpact:
NONE
Description
Velociraptor's SetClientMetadata used the wrong permission check to enforce setting metadata on the server. This allows a user with LABEL_CLIENTS permission to update the server metadata.
Server metadata is often used to store site wide configuration data that should only be updated by the server admin.
Problem
CWE-863: Incorrect Authorization
Required configuration for exposure
This can only be exploited by an authenticated user with the "investigator" role. The usual audit logging will record misuse.
| Product | Affected |
|---|---|
| Rapid7 Velociraptor on
Linux
source repo Default status is unaffected |
before 0.77.3 |
Credits
- Yuval Miller and Leon Kayaliev