CVE 5 MEDIUM

GetUserRoles API endpoint allows any authenticated user to enumerate ACL policies across all organizations_CVE-2026-7573

5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Description

An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 allows any authenticated low-privilege user to retrieve the complete ACL policy (roles and permissions) for any user across all organizations by supplying targeted Name and Org parameters via a network request.

Basic Information

ID CVE-2026-7573
Source rapid7
Published May 6, 2026 at 02:15

Affected Product

Vendor Velocidex
Product velociraptor
Affected Versions Velocidex velociraptor 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.