Velociraptor 的 WatchEvent gRPC API 允许指定从哪个组织(OrgId)流式传输事件。然而,服务器在检查 API 权限时,是将请求者与调用者所属的组织(Caller's Org)进行比对,而不是与请求指定的目标组织(Requested Org)进行比对。这种权限验证逻辑错误导致一个拥有某个组织 API 访问权限的用户,可以读取其他其无权访问的组织的事件数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Rapid7 | Velociraptor | 0 ~ 0.77.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78411 | 6.5 MEDIUM | Velociraptor Server Metadata update with Insufficient Permission Check |
| CVE-2026-78413 | 5.5 MEDIUM | Velociraptor privilege escalation via SysmonLogForward client monitoring artifact |
No comments yet