PT-2026-70218 · Unknown · Velociraptor
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Velociraptor (affected versions not specified)
Description
Velociraptor supports multi-tenant deployments called Orgs, consisting of a ROOT org and optional child orgs. The server incorrectly validates the
ORG ADMIN permission when deleting Orgs, checking the permission within the caller's current ORG rather than the ROOT org. Because administrators of child orgs can add the ORG ADMIN permission to their own ACL token, a child org administrator without ROOT org privileges can delete other orgs.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Velociraptor