Velociraptor's WatchEvent gRPC API can specify the OrgId of the org from which events should be streamed. The server checks the API permissions against the caller's Org instead of the requested Org. This allows a user with API access in one org to read events from another org for which they have no access.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 05 Oct 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Velociraptor's WatchEvent gRPC API can specify the OrgId of the org from which events should be streamed. The server checks the API permissions against the caller's Org instead of the requested Org. This allows a user with API access in one org to read events from another org for which they have no access. | |
| Title | WatchEvent API streams another organization's live events | |
| First Time appeared |
Rapid7
Rapid7 velociraptor |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:rapid7:velociraptor:*:*:linux:*:*:*:*:* | |
| Vendors & Products |
Rapid7
Rapid7 velociraptor |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2026-10-05T16:54:07.484Z
Reserved: 2026-08-24T14:44:50.103Z
Link: CVE-2026-78412
No data.
Status : Received
Published: 2026-10-05T17:17:16.183
Modified: 2026-10-05T17:17:16.183
Link: CVE-2026-78412
No data.
OpenCVE Enrichment
No data.
Weaknesses