CVE-2026-7573
גבוהה 7.7
תיאור (מקור, אנגלית)
An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 allows any authenticated low-privilege user to retrieve the complete ACL policy (roles and permissions) for any user across all organizations by supplying targeted Name and Org parameters via a network request.
מדדים
- CVSS 3.1
-
7.7 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-31/7/2026
- CWE
- CWE-639
מוצרים מושפעים
rapid7: velociraptor; linux: linux kernel