CVE-2026-6863: HTTP Filestore Endpoints Misapply Permissions Across Organizations
Velociraptor versions prior to 0.76.4 contain a cross organization authorization bypass in the HTTP API. A user with only the reader role in the root organization (the lowest authenticated role, holding only READRESULTS permission ) can issue a single authenticated HTTP GET that can read any files from other orgs - even if they have no explicit permissions in the target org.
However, the problem does not occur in reverse - a user with read access to a sub org is unable to read from other org or the root org.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Velociraptorto a version that resolves this vulnerability.Fixed in 0.75.9 - Upgrade
Upgrade
Velociraptorto a version that resolves this vulnerability.Fixed in 0.76.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6863?
CVE-2026-6863 is classified as a high-severity vulnerability due to the potential for unauthorized data access across organizations.
How do I fix CVE-2026-6863?
To mitigate CVE-2026-6863, upgrade Velociraptor to version 0.76.4 or later.
Who is affected by CVE-2026-6863?
CVE-2026-6863 affects users of Velociraptor versions prior to 0.76.4, specifically those with limited permissions.
Can CVE-2026-6863 lead to data breaches?
Yes, CVE-2026-6863 can lead to data breaches by allowing unauthorized users to access sensitive information from other organizations.
What type of vulnerability is CVE-2026-6863?
CVE-2026-6863 is a cross-organization authorization bypass vulnerability in the HTTP API of Velociraptor.