CVE-2026-78412
Received Received - Intake

WatchEvent gRPC API OrgId Permission Bypass in Velociraptor

Vulnerability report for CVE-2026-78412, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Rapid7, Inc.

Description

Velociraptor's WatchEvent gRPC API can specify the OrgId of the org from which events should be streamed. The server checks the API permissions against the caller's Org instead of the requested Org. This allows a user with API access in one org to read events from another org for which they have no access.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Rapid7 Velociraptor 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in Velociraptor's WatchEvent gRPC API. It allows users to stream live events from a specified organization. The server incorrectly checks API permissions against the user's own organization instead of the requested one. This lets an attacker with API access in one organization view events from another organization without authorization.

Detection Guidance

To detect this vulnerability, check Velociraptor server logs for unauthorized access attempts to the WatchEvent gRPC API across different organizations. Monitor API calls specifying OrgId mismatches between the caller and requested organization. Ensure all Velociraptor instances are updated to version 0.77.3 or later.

Impact Analysis

An attacker with API access in one organization could exploit this to read sensitive event data from another organization they are not authorized to access. This could lead to unauthorized data exposure, privacy breaches, or information leaks across organizations.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements like GDPR (data protection) and HIPAA (health information privacy). Organizations using vulnerable versions may face legal penalties, reputational damage, and loss of trust due to data breaches.

Mitigation Strategies

Immediately upgrade Velociraptor to version 0.77.3 or later. Review API access logs for suspicious activity between organizations. Restrict API permissions to the minimum required for users. Apply network-level controls to limit gRPC API exposure if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78412. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart