Sceawere

Vulnerability Detail

CVE-2026-78411UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Velociraptor Unauthorized Server Metadata Modification

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
Rapid7
Product
Velociraptor
Attack Type
CWE-863
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Velociraptor's SetClientMetadata used the wrong permission check to enforce setting metadata on the server. This allows a user with LABEL_CLIENTS permission to update the server metadata. Server metadata is often used to store site wide configuration data that should only be updated by the server admin.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-05T18:17:37.257Z",
  "pubdate": "2026-10-05T18:17:37.257Z",
  "executiveSummary": "Velociraptor contains an improper authorization vulnerability within its API handling, specifically affecting the SetClientMetadata function.\nThe vulnerability allows an authenticated user assigned the LABEL_CLIENTS permission to modify server-wide metadata, an action that should be restricted exclusively to administrative users.\nThis represents a significant privilege escalation risk, as server metadata frequently stores sensitive configuration data governing site-wide operations.\nAn attacker possessing the LABEL_CLIENTS permission can manipulate this configuration to alter server behavior, potentially impacting the integrity of the entire deployment.\nExploitation requires existing authentication with the specified limited administrative role, meaning the attack vector is restricted to users who already hold specific, albeit restricted, privileges.\nThe impact includes unauthorized configuration changes, which may be leveraged to facilitate further system compromise or disrupt security operations within the Velociraptor environment.",
  "technicalDetails": "The root cause of this vulnerability lies in an insufficient access control check within the SetClientMetadata function. The application logic fails to properly validate the caller's authorization scope, incorrectly evaluating the LABEL_CLIENTS permission as sufficient for performing global metadata updates.\nIn the Velociraptor architecture, server metadata acts as a centralized repository for configuration parameters that dictate site-wide functionality and policy enforcement. By design, only users with global administrative privileges should possess the authority to modify these parameters.\nThe exploitation flow begins when an attacker, already possessing a valid session and the LABEL_CLIENTS permission, invokes the SetClientMetadata API endpoint. Because the underlying permission verification logic is flawed, the server-side validation routine improperly authorizes the request based on the client-labelling privilege rather than the administrative privilege.\nOnce the request is authorized, the attacker can supply arbitrary key-value pairs to the server metadata store. This payload can potentially overwrite critical system configurations, alter security policies, or modify operational parameters that dictate how the Velociraptor server interacts with endpoints and data collection routines.\nThe technical implication is an improper privilege boundary enforcement. While LABEL_CLIENTS is intended to allow users to modify metadata associated with individual client hosts or client-specific labels, it should never have been authorized for modification of the global server state. This failure effectively allows a lateral move from limited user management to global configuration management.\nPost-exploitation impact is severe, as the integrity of the server configuration can no longer be guaranteed. Depending on the specific parameters managed via the metadata store, an attacker could potentially influence server-side task scheduling, audit logging configurations, or other high-privilege settings, leading to persistent access or full control over the Velociraptor instance."
}
CVE-2026-78411: Velociraptor Unauthorized Server Metadata Modification (MEDIUM Severity, CVSS: 6.5) | Sceawere