Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3c93-g9g6-p5j4 | Velocidex Velociraptor has an authorization bypass vulnerability |
Wed, 06 May 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 06 May 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Velocidex
Velocidex velociraptor |
|
| Vendors & Products |
Velocidex
Velocidex velociraptor |
Wed, 06 May 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 allows any authenticated low-privilege user to retrieve the complete ACL policy (roles and permissions) for any user across all organizations by supplying targeted Name and Org parameters via a network request. | |
| Title | GetUserRoles API endpoint allows any authenticated user to enumerate ACL policies across all organizations | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2026-05-06T16:17:18.756Z
Reserved: 2026-05-01T00:05:56.823Z
Link: CVE-2026-7573
Updated: 2026-05-06T16:16:51.311Z
Status : Awaiting Analysis
Published: 2026-05-06T03:15:59.440
Modified: 2026-05-07T14:56:04.523
Link: CVE-2026-7573
No data.
OpenCVE Enrichment
Updated: 2026-05-06T09:21:20Z
Github GHSA