Description
Velociraptor's WatchEvent gRPC API can specify the OrgId of the org from which events should be streamed. The server checks the API permissions against the caller's Org instead of the requested Org. This allows a user with API access in one org to read events from another org for which they have no access.
Published: 2026-10-05
Score: 4.9 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Access to Cross-Organization Event Data
Action: Patch
AI Analysis

Impact

Velociraptor’s WatchEvent gRPC API allows a caller to specify the OrgId of the organization whose event stream should be returned. The server incorrectly verifies the caller’s permissions against the caller’s own organization rather than the requested organization, which means that a user with API access in one organization can read live events that belong to any other organization. This represents a breach of confidentiality and can be exploited for data reconnaissance or exfiltration. The weak point is classified as CWE‑639, an authorization bypass via user‑controlled data.

Affected Systems

The product affected is Rapid7 Velociraptor, a Linux‑based security monitoring platform. All unpatched releases of Velociraptor are vulnerable; the advisory does not specify a particular version range.

Risk and Exploitability

The vulnerability carries a CVSS score of 4.9, indicating moderate severity. EPSS is not available, and the issue is not listed in the CISA KEV catalog, suggesting no known large‑scale exploitation yet. The exploit requires only that an attacker possess any valid API token for some organization; with that token, the attacker can request and receive streams from any OrgId directly, making the attack path straightforward for authenticated users. Because the flaw exists in the API permission check, the vulnerability can be abused remotely without additional network access barriers.

Generated by OpenCVE AI on October 5, 2026 at 18:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest Velociraptor release that includes the WatchEvent permission validation fix
  • Revoke or regenerate any API tokens that grant cross‑organization access until the patch is applied
  • Perform an audit of current API permissions and enforce least privilege to ensure no user can access event streams from organizations they are not authorized to view

Generated by OpenCVE AI on October 5, 2026 at 18:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 17:00:00 +0000

Type Values Removed Values Added
Description Velociraptor's WatchEvent gRPC API can specify the OrgId of the org from which events should be streamed. The server checks the API permissions against the caller's Org instead of the requested Org. This allows a user with API access in one org to read events from another org for which they have no access.
Title WatchEvent API streams another organization's live events
First Time appeared Rapid7
Rapid7 velociraptor
Weaknesses CWE-639
CPEs cpe:2.3:a:rapid7:velociraptor:*:*:linux:*:*:*:*:*
Vendors & Products Rapid7
Rapid7 velociraptor
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Rapid7 Velociraptor
cve-icon MITRE

Status: PUBLISHED

Assigner: rapid7

Published:

Updated: 2026-10-05T19:04:43.517Z

Reserved: 2026-08-24T14:44:50.103Z

Link: CVE-2026-78412

cve-icon Vulnrichment

Updated: 2026-10-05T19:04:39.759Z

cve-icon NVD

Status : Received

Published: 2026-10-05T17:17:16.183

Modified: 2026-10-05T20:17:27.013

Link: CVE-2026-78412

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T19:15:10Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key