EN
en direct
Élevée CVSS 8.7

CVE-2026-18860

Analyse NVD en cours

Velociraptor allows multi-tenant deployments named "Orgs". By default Velociraptor, uses the ROOT org, but users can create child orgs for other tenants within the same deployment. Users can have different permissions in each org. To manage Orgs, Velociraptor usually examines the ORG_ADMIN permission on the ROOT org. This issue results from the Velociraptor server allowing for the deletion of Orgs by incorrectly checking the ORG_ADMIN permission of callers within the calling ORG instead of the ROOT org. However, Org admins of child orgs were able to add this permission to their ACL token within their own org. This allows an administrator in a child org, which is not also an administrator in the ROOT org, to delete other orgs.

Ce que ça veut dire

Exposition
Exploitable à distance depuis le réseau, avec un compte privilégié et sans action de la victime.
Impact
Un attaquant peut modifier ou détruire des données et mettre le service hors ligne. L’atteinte déborde du composant vulnérable vers d’autres parties du système.
Probabilité
Le score EPSS reste bas : rien n’annonce une exploitation imminente, ce qui ne dispense pas de corriger.

À faireÀ intégrer au prochain cycle de correctifs.

Lecture automatique du vecteur CVSS, du type de faiblesse (CWE) et du score EPSS. La description technique ci-dessus reste celle publiée par le NIST, en anglais.

Publié
11 août 2026
CVSS
8.7 (v3.1) CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H
EPSS
0,3 % probabilité d'exploitation sous 30 jours · au-dessus de 23 % des CVE
Faiblesse
CWE-280
Sources
nvd
Références

Tapez au moins deux caractères.

naviguer ouvrir esc fermer