However, the problem does not occur in reverse - a user with read access to a sub org is unable to read from other org or the root org.
Project Subscriptions
No data.
No advisories yet.
Solution
To remediate, you will need to upgrade your server https://docs.velociraptor.app/docs/deployment/server/upgrades/#upgrading-a-server-in-place-upgrade to the latest version of your release: * For 0.76 releases, upgrade immediately to v0.76.4 https://github.com/Velocidex/velociraptor/releases/download/v0.76/velociraptor-v0.76.4-linux-amd64 * For 0.75 releases, upgrade immediately to v0.75.9 https://github.com/Velocidex/velociraptor/releases/download/v0.75/velociraptor-v0.75.9-linux-amd64
Workaround
No workaround given by the vendor.
Wed, 06 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Velociraptor versions prior to 0.76.4 contain a cross organization authorization bypass in the HTTP API. A user with only the reader role in the root organization (the lowest authenticated role, holding only READ_RESULTS permission ) can issue a single authenticated HTTP GET that can read any files from other orgs - even if they have no explicit permissions in the target org. However, the problem does not occur in reverse - a user with read access to a sub org is unable to read from other org or the root org. | |
| Title | HTTP Filestore Endpoints Misapply Permissions Across Organizations | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2026-05-06T15:27:40.088Z
Reserved: 2026-04-22T14:25:24.122Z
Link: CVE-2026-6863
No data.
Status : Received
Published: 2026-05-06T16:16:12.030
Modified: 2026-05-06T16:16:12.030
Link: CVE-2026-6863
No data.
OpenCVE Enrichment
Updated: 2026-05-06T16:30:06Z