CVE-2026-78412: WatchEvent API streams another organization's live events
Published Oct 5, 2026
·Updated
Velociraptor's WatchEvent gRPC API can specify the OrgId of the org from which events should be streamed. The server checks the API permissions against the caller's Org instead of the requested Org. This allows a user with API access in one org to read events from another org for which they have no access.
Affected Software
1 affected component
Velocidex Velociraptor
Event History
Oct 5, 2026
CVE Published
via MITRE·04:51 PM
Data Sourced
via MITRE·04:51 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attacker needs API access in any organization. They do not need access to the organization whose events they request.
2
What information can be exposed?
An attacker can read live events streamed from another organization by specifying that organization's OrgId in the WatchEvent gRPC API request.