Velociraptor's WatchEvent gRPC API can specify the OrgId of the org from which events should be streamed. The server checks the API permissions against the caller's Org instead of the requested Org. This allows a user with API access in one org to read events from another org for which they have no access.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 05 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 17:00:00 +0000

Type Values Removed Values Added
Description Velociraptor's WatchEvent gRPC API can specify the OrgId of the org from which events should be streamed. The server checks the API permissions against the caller's Org instead of the requested Org. This allows a user with API access in one org to read events from another org for which they have no access.
Title WatchEvent API streams another organization's live events
First Time appeared Rapid7
Rapid7 velociraptor
Weaknesses CWE-639
CPEs cpe:2.3:a:rapid7:velociraptor:*:*:linux:*:*:*:*:*
Vendors & Products Rapid7
Rapid7 velociraptor
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: rapid7

Published:

Updated: 2026-10-05T19:04:43.517Z

Reserved: 2026-08-24T14:44:50.103Z

Link: CVE-2026-78412

cve-icon Vulnrichment

Updated: 2026-10-05T19:04:39.759Z

cve-icon NVD

Status : Received

Published: 2026-10-05T17:17:16.183

Modified: 2026-10-05T17:17:16.183

Link: CVE-2026-78412

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T19:15:10Z

Weaknesses