AI analysis
Velociraptor’s SetClientMetadata API enforces the wrong permission when metadata is written on the server. A user who already has the LABEL_CLIENTS permission can change server metadata over the network without further interaction. That metadata commonly holds site-wide configuration that only a server administrator should be able to update, so the impact is unauthorized integrity changes to central configuration (CVSS 3.1 base score 6.5; CWE-863), not confidentiality or availability loss. Rapid7 Velociraptor deployments that grant LABEL_CLIENTS to non-admins are affected; affected version ranges are not stated in the supplied data. It is not listed in CISA KEV and no public proof-of-concept is known.
What to do: Apply the fix from Rapid7 advisory AV26-1004 as soon as a patched Velociraptor build is available for your deployment. Until then, limit who holds LABEL_CLIENTS, and review server metadata for unexpected site-wide configuration changes by non-admin users.
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Velociraptor's SetClientMetadata used the wrong permission check to enforce setting metadata on the server. This allows a user with LABEL_CLIENTS permission to update the server metadata. Server metadata is often used to store site wide configuration data that should only be updated by the server admin.