Rapid7 security advisory (AV26-1004)
Canada's Cyber Centre warns Rapid7 Velociraptor before 0.77.3 has insufficient permission checks (CVE-2026-78411).
On October 6, 2026, the Canadian Centre for Cyber Security issued advisory AV26-1004 for Rapid7 Velociraptor. Versions before 0.77.3 are affected by CVE-2026-78411, a server metadata update with an insufficient permission check. The centre urges administrators to review Rapid7's advisory and apply updates. No active exploitation is mentioned.
- Advisory AV26-1004 covers Velociraptor versions before 0.77.3.
- CVE-2026-78411 is an insufficient permission check on server metadata updates.
- Administrators should apply available updates; exploitation is not reported.
Vulnerabilities mentionedAll →
- CVE-2026-784116.5—Incorrect authorization in Velociraptor server metadatapublished · Rapid7 Velociraptor
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-78411 | Incorrect authorization in Velociraptor server metadata Velociraptor’s SetClientMetadata API enforces the wrong permission when metadata is written on the server. A user who already has the LABEL_CLIENTS permission can change server metadata over the network without further interaction. That metadata commonly holds site-wide configuration that only a server administrator should be able to update, so the impact is unauthorized integrity changes to central configuration (CVSS 3.1 base score 6.5; CWE-863), not confidentiality or availability loss. Rapid7 Velociraptor deployments that grant LABEL_CLIENTS to non-admins are affected; affected version ranges are not stated in the supplied data. It is not listed in CISA KEV and no public proof-of-concept is known. Apply the fix from Rapid7 advisory AV26-1004 as soon as a patched Velociraptor build is available for your deployment. Until then, limit who holds LABEL_CLIENTS, and review server metadata for unexpected site-wide configuration changes by non-admin users. |
Full article60 words · extracted from cyber.gc.ca · click to collapse
Serial Number: AV26-1004
Date: October 6, 2026
As of October 5, 2026, Rapid7 is affected by a vulnerability in the following product:
- Velociraptor
- Prior to 0.77.3
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/rapid7-security-advisory-av26-1004