CVE-2026-78411
Rapid7 Velociraptor
Published 5 Oct 2026 · updated 5 Oct 2026 · Received
6.5 Medium · CVSS 3.1, rapid7.com
Description
Velociraptor's SetClientMetadata used the wrong permission check to enforce setting metadata on the server. This allows a user with LABEL_CLIENTS permission to update the server metadata. Server metadata is often used to store site wide configuration data that should only be updated by the server admin.