CVE-2026-7573: GetUserRoles API endpoint allows any authenticated user to enumerate ACL policies across all organizations
An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 allows any authenticated low-privilege user to retrieve the complete ACL policy (roles and permissions) for any user across all organizations by supplying targeted Name and Org parameters via a network request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7573?
CVE-2026-7573 has a moderate severity level due to the potential for unauthorized enumeration of ACL policies.
How do I fix CVE-2026-7573?
To fix CVE-2026-7573, upgrade Velocidex Velociraptor to version 0.76.5 or later.
What versions of Velocidex Velociraptor are affected by CVE-2026-7573?
CVE-2026-7573 affects all versions of Velocidex Velociraptor below version 0.76.5.
What type of vulnerability is CVE-2026-7573?
CVE-2026-7573 is classified as an authorization bypass vulnerability (CWE-639).
What impact does CVE-2026-7573 have on system security?
CVE-2026-7573 allows low-privilege users to access sensitive ACL policy information, potentially leading to privilege escalation.