CVE-2026-78412
WatchEvent API streams another organization's live events
CVSS Score
4.9
EPSS Score
0.0%
EPSS Percentile
0th
Velociraptor's WatchEvent gRPC API can specify the OrgId of the org from which events should be streamed. The server checks the API permissions against the caller's Org instead of the requested Org. This allows a user with API access in one org to read events from another org for which they have no access.
| CWE | CWE-639 |
| Vendor | rapid7 |
| Product | velociraptor |
| Published | Oct 5, 2026 |
| Last Updated | Oct 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for rapid7 velociraptor
Be the first to know when new medium vulnerabilities affecting rapid7 velociraptor are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
Rapid7 / Velociraptor
0 < 0.77.3