๐Ÿ” CVE Alert

CVE-2026-78411

MEDIUM 6.5

Velociraptor Server Metadata update with Insufficient Permission Check

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

Velociraptor's SetClientMetadata used the wrong permission check to enforce setting metadata on the server. This allows a user with LABEL_CLIENTS permission to update the server metadata. Server metadata is often used to store site wide configuration data that should only be updated by the server admin.

CWE CWE-863
Vendor rapid7
Product velociraptor
Published Oct 5, 2026
Last Updated Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for rapid7 velociraptor

Be the first to know when new medium vulnerabilities affecting rapid7 velociraptor are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None

Affected Versions

Rapid7 / Velociraptor
0 < 0.77.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
docs.velociraptor.app: http://docs.velociraptor.app/announcements/advisories/cve-2026-78411

Credits

Yuval Miller Leon Kayaliev