CVE-2026-78411
Received Received - Intake

Incorrect SetClientMetadata Permission Check in Velociraptor Allows Metadata Modification

Vulnerability report for CVE-2026-78411, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Rapid7, Inc.

Description

Velociraptor's SetClientMetadata used the wrong permission check to enforce setting metadata on the server. This allows a user with LABEL_CLIENTS permission to update the server metadata. Server metadata is often used to store site wide configuration data that should only be updated by the server admin.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Rapid7 Velociraptor 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Velociraptor Server involves the SetClientMetadata function using an incorrect permission check. It allows users with LABEL_CLIENTS permission to update server metadata, which should only be modifiable by server administrators.

Detection Guidance

Check Velociraptor server logs for unauthorized metadata updates by users with LABEL_CLIENTS permission. Review server metadata changes via Velociraptor's admin interface or API to identify suspicious activity.

Impact Analysis

An attacker with LABEL_CLIENTS permission could modify server metadata, potentially altering site-wide configuration settings. This could lead to unauthorized changes in system behavior or security settings.

Compliance Impact

This vulnerability does not directly impact GDPR or HIPAA compliance as it involves unauthorized modification of server metadata by users with limited permissions. However, it could indirectly affect compliance by allowing unauthorized changes to configuration data that may include settings relevant to data protection policies.

Mitigation Strategies

Update Velociraptor to version 0.77.3 or later. Restrict LABEL_CLIENTS permission to only trusted administrators. Monitor server metadata for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78411. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart