CVE-2026-78412Medium· 4.9▾ SunlitVelociraptor's WatchEvent gRPC API can specify the OrgId of the org from which events should be streamed. The server checks the API permissions against the caller's Org instead of the requested Org. This allows a user with API access in …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Velociraptor's WatchEvent gRPC API can specify the OrgId of the org from which events should be streamed. The server checks the API permissions against the caller's Org instead of the requested Org. This allows a user with API access in one org to read events from another org for which they have no access.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-78413Medium· 5.5Velociraptor allows collection of VQL queries packaged into Artifacts from endpoints
CVE-2026-78411Medium· 6.5Velociraptor's SetClientMetadata used the wrong permission check to enforce setting metadata on the server
CVE-2026-77797Low· 3.6Velociraptor's prefetch library contains an out of bound vulnerability which may cause a crash when parsing certain malformed prefetch files.
CVE-2026-77798Medium· 6.5Velociraptor contains a deadlock condition that may be triggered by authenticated users
CVE-2026-19072Critical· 9.9Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each endpoint in the hunt
CVE-2026-19584High· 7.7Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature