Impact
Velociraptor’s WatchEvent gRPC API allows a caller to specify the OrgId of the organization whose event stream should be returned. The server incorrectly verifies the caller’s permissions against the caller’s own organization rather than the requested organization, which means that a user with API access in one organization can read live events that belong to any other organization. This represents a breach of confidentiality and can be exploited for data reconnaissance or exfiltration. The weak point is classified as CWE‑639, an authorization bypass via user‑controlled data.
Affected Systems
The product affected is Rapid7 Velociraptor, a Linux‑based security monitoring platform. All unpatched releases of Velociraptor are vulnerable; the advisory does not specify a particular version range.
Risk and Exploitability
The vulnerability carries a CVSS score of 4.9, indicating moderate severity. EPSS is not available, and the issue is not listed in the CISA KEV catalog, suggesting no known large‑scale exploitation yet. The exploit requires only that an attacker possess any valid API token for some organization; with that token, the attacker can request and receive streams from any OrgId directly, making the attack path straightforward for authenticated users. Because the flaw exists in the API permission check, the vulnerability can be abused remotely without additional network access barriers.
OpenCVE Enrichment