{"id":"CVE-2026-78411","title":"Velociraptor's SetClientMetadata used the wrong permission check to enforce setting metadata on the server","summary":"Velociraptor's SetClientMetadata used the wrong permission check to enforce setting metadata on the server. This allows a user with LABEL_CLIENTS permission to update the server metadata.\n\nServer metadata is often used to store site wide…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","cwe":["CWE-863"],"vendor":"Rapid7","product":"Velociraptor","affected":["Velociraptor < 0.77.3"],"published":"2026-10-05","updated":"2026-10-05","sourceUpdated":"2026-10-05T18:17:37.257","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-78411","references":[{"url":"http://docs.velociraptor.app/announcements/advisories/cve-2026-78411","label":"cve@rapid7.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-05T17:27:45.056Z","slug":"CVE-2026-78411","body":"## Overview\n\nVelociraptor's SetClientMetadata used the wrong permission check to enforce setting metadata on the server. This allows a user with LABEL_CLIENTS permission to update the server metadata.\n\nServer metadata is often used to store site wide configuration data that should only be updated by the server admin.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}