Executive brief
Velociraptor is a digital forensics and endpoint monitoring platform used by security teams to investigate incidents and collect evidence from computers. An authenticated attacker can hijack another user's identity by forging a custom HTTP header, potentially escalating from a regular user account to administrative privileges and gaining full control of the system.
Technical details
This is an authentication bypass / identity spoofing vulnerability in the Velociraptor GUI. An authenticated attacker can send a specially crafted request with the "Grpc-Metadata-USER" custom header to spoof the identity of another user, including administrators. The vulnerability allows privilege escalation from a low-privileged authenticated user to administrator level. The attack requires the attacker to already have valid authentication credentials and network access to the GUI. Velociraptor has released version 0.77.2 as a patch for this vulnerability.
Affected products
- Velociraptor Velociraptor before 0.77.2
Timeline
- 2026-08-11: disclosed
- 2026-08-11: patched: Fix available in version 0.77.2