CVE-2026-78411

Rapid7 Velociraptor

Published 5 Oct 2026 · updated 5 Oct 2026 · Received

6.5 Medium · CVSS 3.1, rapid7.com

Description

Velociraptor's SetClientMetadata used the wrong permission check to enforce setting metadata on the server. This allows a user with LABEL_CLIENTS permission to update the server metadata. Server metadata is often used to store site wide configuration data that should only be updated by the server admin.

References