CVE-2026-78412: WatchEvent API streams another organization's live events
Published on 2026-07-31
Vulnogram
CVSS · MEDIUM · 4.9 ⁄10 · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Scoring scenario:
GENERAL
attackVector:
NETWORK
attackComplexity:
LOW
privilegesRequired:
HIGH
userInteraction:
NONE
scope:
UNCHANGED
confidentialityImpact:
HIGH
integrityImpact:
NONE
availabilityImpact:
NONE
Description
Velociraptor's WatchEvent gRPC API can specify the OrgId of the org from which events should be streamed. The server checks the API permissions against the caller's Org instead of the requested Org. This allows a user with API access in one org to read events from another org for which they have no access.
Problem
CWE-639 Authorization bypass through User-Controlled key
Required configuration for exposure
The attacker needs to have gRPC API access to any org on the server.
| Product | Affected |
|---|---|
| Rapid7 Velociraptor on
Linux
source repo Default status is unaffected |
before 0.77.3 |
Credits
- Yuval Miller and Leon Kayaliev