{
  "id": "CVE-2026-78412",
  "url": "https://spydr.io/cve/CVE-2026-78412",
  "published": "2026-10-05T17:17:16.183Z",
  "modified": "2026-10-05T20:17:27.013Z",
  "score": 4.9,
  "severity": "medium",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
  "score_source": "rapid7.com",
  "epss": null,
  "epss_percentile": null,
  "exploited": false,
  "kev": null,
  "ssvc_exploitation": "none",
  "vendors": [
    "Rapid7"
  ],
  "products": [
    "Rapid7 Velociraptor"
  ],
  "cwes": [
    "CWE-639"
  ],
  "description": "Velociraptor's WatchEvent gRPC API can specify the OrgId of the org from which events should be streamed. The server checks the API permissions against the caller's Org instead of the requested Org. This allows a user with API access in one org to read events from another org for which they have no access.",
  "status": "Received",
  "score_type": "Secondary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 4.9,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "http://docs.velociraptor.app/announcements/advisories/cve-2026-78412",
      "tags": []
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78412",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
