CVE-2026-78411: medium-severity vulnerability in Rapid7 Velociraptor
Velociraptor Server Metadata update with Insufficient Permission Check
Published
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.5epss 0.2%
exploitation probability
0.2%top 94% of all CVEs
observed exploitation
nono source reports it
Velociraptor's SetClientMetadata used the wrong permission check to enforce setting metadata on the server. This allows a user with LABEL_CLIENTS permission to update the server metadata.
Server metadata is often used to store site wide configuration data that should only be updated by the server admin.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Affected products
Rapid7 · VelociraptorRelated CVEs — Rapid7 Velociraptor
In the same product, most dangerous first.
CVE-2025-6264MEDIUMVelociraptor priviledge escalation via UpdateConfig artifactEPSS 1.0%CVE-2023-0290MEDIUMRapid7 Velociraptor directory traversal in client ID parameter EPSS 0.7%CVE-2026-5329HIGHRapid7 Velociraptor Improper Input Validation in Client Message HandlerEPSS 0.6%CVE-2026-19583CRITICALVelociraptor Required Permissions bypass by using client monitoring queriesEPSS 0.6%CVE-2021-3619LOWRapid7 Velociraptor Notebooks Authenticated Persistent XSSEPSS 0.6%CVE-2025-14728MEDIUMRapid7 Velociraptor Directory Traversal VulnerabilityEPSS 0.6%