CVE-2026-78411

Velociraptor's SetClientMetadata used the wrong permission check to enforce setting metadata on the server. This allows a user with LABEL_CLIENTS permission to update the server metadata. Server metadata is often used to store site wide configuration data that should only be updated by the server admin.

  • Published Oct 5, 2026
  • CVSS 6.5 medium

Affected software

CVE-2026-78411 at the National Vulnerability Database