Impact
Velociraptor enables multi‑tenant deployments by creating hierarchical organisations (Orgs). The bug allows an administrator in a child org to delete any other org because the system incorrectly checks the ORG_ADMIN permission against the caller’s current org instead of the ROOT org. This bypasses the intended restriction and permits deletion of unrelated organisations, compromising data integrity and service availability. The flaw is a classic authorization check failure, identified as CWE‑280.
Affected Systems
The vulnerability affects Rapid7 Velociraptor installations that use child organisations for multi‑tenant support. No specific product version information is provided; any deployment that enables Org admin roles in child organisations is potentially impacted unless mitigated by configuration changes.
Risk and Exploitability
The CVSS score of 8.7 indicates a high‑severity risk. EPSS data is not available, but the issue is not listed in the CISA KEV catalog, suggesting no widespread exploitation yet. Attackers need only the rights of a child‑org administrator to trigger the exploit, so the attack vector is within‑instance privilege escalation rather than external network access. Once exploited, the attacker can remove other organisations, leading to loss of data and disruption of tenant services.
OpenCVE Enrichment