Skip to content
Please update to the latest release 0.77.3 to address Multiple CVEs.

CVE-2026-78412: WatchEvent API streams another organization's live events

Published on 2026-07-31 Vulnogram
Description

Velociraptor's WatchEvent gRPC API can specify the OrgId of the org from which events should be streamed. The server checks the API permissions against the caller's Org instead of the requested Org. This allows a user with API access in one org to read events from another org for which they have no access.

Problem CWE-639 Authorization bypass through User-Controlled key
Required configuration for exposure The attacker needs to have gRPC API access to any org on the server.
ProductAffected
Rapid7 Velociraptor on Linux
source repo
Default status is unaffected
before 0.77.3
Credits
  • Yuval Miller and Leon Kayaliev