Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 Oct 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Velociraptor's WatchEvent gRPC API can specify the OrgId of the org from which events should be streamed. The server checks the API permissions against the caller's Org instead of the requested Org. This allows a user with API access in one org to read events from another org for which they have no access. | |
| Title | WatchEvent API streams another organization's live events | |
| First Time appeared |
Rapid7
Rapid7 velociraptor |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:rapid7:velociraptor:*:*:linux:*:*:*:*:* | |
| Vendors & Products |
Rapid7
Rapid7 velociraptor |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2026-10-05T19:04:43.517Z
Reserved: 2026-08-24T14:44:50.103Z
Link: CVE-2026-78412
Updated: 2026-10-05T19:04:39.759Z
Status : Received
Published: 2026-10-05T17:17:16.183
Modified: 2026-10-05T20:17:27.013
Link: CVE-2026-78412
No data.
OpenCVE Enrichment
Updated: 2026-10-05T19:15:10Z
-
CWE-639
Authorization Bypass Through User-Controlled Key