Full Report
Rapid7 security advisory (AV26-1004)
Analysis Summary
# Vulnerability: Rapid7 Velociraptor Insufficient Permission Check in Server Metadata
## CVE Details
- **CVE ID:** CVE-2026-78411
- **CVSS Score:** Not explicitly listed in the advisory (Estimated High based on "Insufficient Permission Check" impacts)
- **CWE:** CWE-285 (Improper Authorization)
## Affected Systems
- **Products:** Rapid7 Velociraptor
- **Versions:** All versions prior to 0.77.3
- **Configurations:** Systems running the Velociraptor Server component where metadata updates are processed.
## Vulnerability Description
The vulnerability stems from an **Insufficient Permission Check** during the Velociraptor Server metadata update process. In affected versions, the application fails to adequately verify the authorization levels of a user or process attempting to modify server-side metadata. This could allow an attacker with limited privileges to perform actions or modify configurations that should be restricted to administrative roles.
## Exploitation
- **Status:** Not explicitly reported as exploited in the wild (per this advisory); PoC status not disclosed.
- **Complexity:** Medium
- **Attack Vector:** Network (typically requires access to the Velociraptor management interface or API).
## Impact
- **Confidentiality:** Moderate (Potential access to sensitive server configuration data).
- **Integrity:** High (Unauthorized modification of server metadata and operational parameters).
- **Availability:** Moderate (Potential for service disruption through configuration tampering).
## Remediation
### Patches
- **Velociraptor 0.77.3:** Rapid7 has released version 0.77.3 which addresses this vulnerability by implementing stricter permission checks. Users are urged to upgrade immediately.
### Workarounds
- No official functional workarounds have been provided. Remediation requires a binary update to the server component.
- **Immediate Action:** Restrict access to the Velociraptor GUI and API to trusted administrative IP addresses only.
## Detection
- **Indicators of Compromise:** Monitor audit logs for unusual metadata update activities originating from non-admin accounts.
- **Detection methods:** Review Velociraptor server logs for `Server.Metadata.Update` events and cross-reference them against authorized administrative change windows.
## References
- **Vendor Advisory:** hxxps[://]docs[.]velociraptor[.]app/announcements/advisories/cve-2026-78411/
- **Rapid7 Security Repository:** hxxps[://]docs[.]velociraptor[.]app/announcements/advisories/
- **Cyber Centre Bulletin:** hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/rapid7-security-advisory-av26-1004