However, the problem does not occur in reverse - a user with read access to a sub org is unable to read from other org or the root org.
No advisories yet.
Solution
To remediate, you will need to upgrade your server https://docs.velociraptor.app/docs/deployment/server/upgrades/#upgrading-a-server-in-place-upgrade to the latest version of your release: * For 0.76 releases, upgrade immediately to v0.76.4 https://github.com/Velocidex/velociraptor/releases/download/v0.76/velociraptor-v0.76.4-linux-amd64 * For 0.75 releases, upgrade immediately to v0.75.9 https://github.com/Velocidex/velociraptor/releases/download/v0.75/velociraptor-v0.75.9-linux-amd64
Workaround
No workaround given by the vendor.
Wed, 06 May 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rapid7
Rapid7 velociraptor |
|
| Vendors & Products |
Rapid7
Rapid7 velociraptor |
Wed, 06 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Velociraptor versions prior to 0.76.4 contain a cross organization authorization bypass in the HTTP API. A user with only the reader role in the root organization (the lowest authenticated role, holding only READ_RESULTS permission ) can issue a single authenticated HTTP GET that can read any files from other orgs - even if they have no explicit permissions in the target org. However, the problem does not occur in reverse - a user with read access to a sub org is unable to read from other org or the root org. | |
| Title | HTTP Filestore Endpoints Misapply Permissions Across Organizations | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2026-05-06T15:27:40.088Z
Reserved: 2026-04-22T14:25:24.122Z
Link: CVE-2026-6863
No data.
Status : Received
Published: 2026-05-06T16:16:12.030
Modified: 2026-05-06T16:16:12.030
Link: CVE-2026-6863
No data.
OpenCVE Enrichment
Updated: 2026-05-06T23:00:14Z