Sceawere

Vulnerability Detail

CVE-2026-78412UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Velociraptor Unauthorized Cross-Org Event Access

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.9
Creation Date
2h ago
Vendor
Rapid7
Product
Velociraptor
Attack Type
CWE-639 Authorization bypass through User-Controlled key
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Velociraptor's WatchEvent gRPC API can specify the OrgId of the org from which events should be streamed. The server checks the API permissions against the caller's Org instead of the requested Org. This allows a user with API access in one org to read events from another org for which they have no access.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.9",
  "pubDate": "2026-10-05T17:17:16.183Z",
  "pubdate": "2026-10-05T17:17:16.183Z",
  "executiveSummary": "This vulnerability is an Improper Authorization flaw within the Velociraptor WatchEvent gRPC API, specifically related to multi-tenancy logical isolation.\nThe issue stems from a failure in the server-side access control validation logic, which validates the requestor's permissions against their originating organization rather than the target organization specified in the gRPC request.\nAn authenticated user with API access in a single organization can successfully subscribe to and stream events from other organizations they are not authorized to access.\nThe impact includes unauthorized information disclosure of sensitive telemetry, system logs, and security events across organizational boundaries, severely compromising the multi-tenancy security posture of the platform.\nExploitation requires active API credentials within the system and the ability to interface with the WatchEvent gRPC endpoint. No specialized exploit code is required beyond standard gRPC client requests to manipulate the OrgId parameter.\nThis represents a significant risk to data confidentiality in deployments utilizing Velociraptor's organizational separation features.",
  "technicalDetails": "The vulnerability resides within the Velociraptor server's gRPC request handling logic for the WatchEvent API. The API is designed to allow clients to subscribe to event streams; however, the request schema allows the caller to define the 'OrgId' parameter, designating the target organization from which the event stream should be sourced.\nThe root cause is a deficiency in the authorization enforcement mechanism. When a request is received, the server attempts to verify the caller's privileges; however, the access control check is performed against the context of the caller's authenticated organization (the 'Subject' Org) rather than validating that the caller holds the appropriate permissions within the target organization (the 'Object' Org).\nThis logical decoupling allows a malicious or compromised API key—possessing sufficient 'read' privileges within their own organization—to bypass authorization boundaries. By sending a gRPC request to the WatchEvent endpoint with a modified 'OrgId' field, the attacker instructs the server to attach the subscriber to the event bus of an unauthorized organization.\nAttack flow: 1. The attacker authenticates with their legitimate, albeit restricted, API credentials. 2. The attacker initiates a gRPC WatchEvent call. 3. The attacker crafts the request payload, explicitly setting the 'OrgId' field to an identifier corresponding to a target organization they wish to monitor. 4. The server-side authentication middleware validates the user's token but incorrectly associates the authorization check with the user's home organization. 5. The server grants the subscription request, effectively hooking the attacker's gRPC stream into the target organization's event pipeline. 6. The attacker receives a continuous flow of sensitive event data originating from the target organization, which may include system metadata, endpoint activity, and other potentially confidential telemetry.\nThe vulnerability exists at the gRPC service layer, specifically within the WatchEvent implementation. It affects any deployment where multiple organizations are hosted on a single Velociraptor instance. Because the vulnerability is logic-based, it persists regardless of the network-layer configuration, as long as the gRPC interface is reachable by authenticated users."
}
CVE-2026-78412: Velociraptor Unauthorized Cross-Org Event Access (MEDIUM Severity, CVSS: 4.9) | Sceawere