Executive brief
Velociraptor, an open-source endpoint monitoring and digital forensics platform, contains a security flaw in its internal communication system. An attacker with basic user access can bypass security checks to view the specific permissions and roles assigned to any other user across the entire organization. While this does not grant direct control over other accounts, it allows an attacker to identify high-privilege targets for further specialized attacks.
Technical details
An authorization bypass (CWE-639) exists in the GetUserRoles gRPC API endpoint of Velocidex Velociraptor. The vulnerability is rooted in insufficient validation of user-controlled 'Name' and 'Org' parameters during API requests. A network-based attacker with low-level authenticated access can supply targeted parameters to retrieve the complete Access Control List (ACL) policy, including roles and permissions, for any user across all organizations. While the attacker must know the target's organization ID and username, the exploit allows for the enumeration of high-privilege accounts. The issue is resolved in version 0.76.5.
Affected products
- Velocidex Velociraptor < 0.76.5
Timeline
- 2026-05-04: advisory: Vendor advisory published by Rapid7/Velociraptor
- 2026-05-06: disclosed: CVE published to NVD