However, the problem does not occur in reverse - a user with read access to a sub org is unable to read from other org or the root org.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
To remediate, you will need to upgrade your server https://docs.velociraptor.app/docs/deployment/server/upgrades/#upgrading-a-server-in-place-upgrade to the latest version of your release: * For 0.76 releases, upgrade immediately to v0.76.4 https://github.com/Velocidex/velociraptor/releases/download/v0.76/velociraptor-v0.76.4-linux-amd64 * For 0.75 releases, upgrade immediately to v0.75.9 https://github.com/Velocidex/velociraptor/releases/download/v0.75/velociraptor-v0.75.9-linux-amd64
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-2v93-vp82-cjv8 | Velocidex Velociraptor has an Incorrect Authorization issue |
Thu, 07 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 06 May 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rapid7
Rapid7 velociraptor |
|
| Vendors & Products |
Rapid7
Rapid7 velociraptor |
Wed, 06 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Velociraptor versions prior to 0.76.4 contain a cross organization authorization bypass in the HTTP API. A user with only the reader role in the root organization (the lowest authenticated role, holding only READ_RESULTS permission ) can issue a single authenticated HTTP GET that can read any files from other orgs - even if they have no explicit permissions in the target org. However, the problem does not occur in reverse - a user with read access to a sub org is unable to read from other org or the root org. | |
| Title | HTTP Filestore Endpoints Misapply Permissions Across Organizations | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2026-05-06T15:27:40.088Z
Reserved: 2026-04-22T14:25:24.122Z
Link: CVE-2026-6863
Updated: 2026-05-06T15:27:36.566Z
Status : Awaiting Analysis
Published: 2026-05-06T16:16:12.030
Modified: 2026-05-07T14:56:04.523
Link: CVE-2026-6863
No data.
OpenCVE Enrichment
Updated: 2026-05-06T23:00:14Z
Github GHSA