CVE-2026-78411: RAPID7 Velociraptor
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Velociraptor's SetClientMetadata used the wrong permission check to enforce setting metadata on the server. This allows a user with LABEL_CLIENTS permission to update the server metadata. Server metadata is often used to store site wide configuration data that should only be updated by the server admin.
Affected products
- RAPID7 Velociraptor: before 0.77.3 (fixed in 0.77.3)
Published 2026-10-05. Last modified 2026-10-06.