Impact
Velociraptor’s multi‑tenant store places child organization data under a common datastore directory. The GUI request path for stacked result sets is not correctly checked against the defined deny list, so a user who can read the root organization can retrieve files belonging to child organizations. The flaw enables unauthorized disclosure of stored result sets, effectively allowing a privileged user to access data that should be confined to a specific sub‑org. The weakness is a classic example of improper access control leading to information leakage.
Affected Systems
Rapid7 Velociraptor is the only listed vendor. The vulnerability impacts any deployment that enables the root organization to grant read permissions. No specific version information is provided, so all releases that have the described directory structure and GUI download logic are potentially affected.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate risk, and the EPSS score of <1% and absence from the CISA KEV catalog suggest that exploit activity has not been observed widely yet. The attack vector requires that the adversary first acquire read or higher privilege on the root org, a condition that may be limited to trusted personnel. Once in place, the path traversal bypass can be exploited with a simple GUI request, making this a low effort, low severity data‑exposure attack that can be mitigated by tightening root‑org permissions.
OpenCVE Enrichment