Velociraptor 中的 函数使用了错误的权限检查机制,未能正确阻止非授权用户设置元数据。该漏洞使得拥有 权限的用户也能够更新服务器元数据。 服务器元数据通常用于存储仅应由服务器管理员进行更新的全站配置信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Rapid7 | Velociraptor | 0 ~ 0.77.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78413 | 5.5 MEDIUM | Velociraptor privilege escalation via SysmonLogForward client monitoring artifact |
| CVE-2026-78412 | 4.9 MEDIUM | WatchEvent API streams another organization's live events |
No comments yet