PT-2026-70218 · Unknown · Velociraptor

·

CVE-2026-18860

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Velociraptor (affected versions not specified)
Description Velociraptor supports multi-tenant deployments called Orgs, consisting of a ROOT org and optional child orgs. The server incorrectly validates the ORG ADMIN permission when deleting Orgs, checking the permission within the caller's current ORG rather than the ROOT org. Because administrators of child orgs can add the ORG ADMIN permission to their own ACL token, a child org administrator without ROOT org privileges can delete other orgs.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18860

Affected Products

Velociraptor