CVE-2026-18860
Last modified
CVE-2026-18860 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. Velociraptor allows multi-tenant deployments named "Orgs". By default Velociraptor, uses the ROOT org, but users can create child orgs for other tenants within the same deployment. Users can have different permissions in each org. To manage Orgs, Velociraptor usually examines the ORG_ADMIN permission on the ROOT org. This issue results from the Velociraptor server allowing for the deletion of Orgs by incorrectly checking the ORG_ADMIN permission of callers within the calling ORG instead of the ROOT org. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
Velociraptor allows multi-tenant deployments named "Orgs". By default Velociraptor, uses the ROOT org, but users can create child orgs for other tenants within the same deployment. Users can have different permissions in each org. To manage Orgs, Velociraptor usually examines the ORG_ADMIN permission on the ROOT org. This issue results from the Velociraptor server allowing for the deletion of Orgs by incorrectly checking the ORG_ADMIN permission of callers within the calling ORG instead of the ROOT org. However, Org admins of child orgs were able to add this permission to their ACL token within their own org. This allows an administrator in a child org, which is not also an administrator in the ROOT org, to delete other orgs.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Rapid7 | Velociraptor | < 0.77.2 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-18860?
How severe is CVE-2026-18860?
How do I fix CVE-2026-18860?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-18855The Link Library plugin for WordPress is vulnerable to arbit…9.1
- CVE-2026-18856A vulnerability was determined in Poesis Rhymix CMS up to 2.…4.7
- CVE-2026-18857IBM OPENBMC FW1120.00 through FW1120.01, FW1110.00 through F…3.4
- CVE-2026-18858IBM i 7.6, and 7.5 could allow a local authenticated attacke…5.5
- CVE-2026-18859A vulnerability was identified in ESAFENET CDG up to 2026061…7.3
- CVE-2026-1886The Go Night Pro | WordPress Dark Mode Plugin for WordPress …6.4
- CVE-2026-18862Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-18869IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authentica…6.4
- CVE-2026-18870IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.0…4.3
- CVE-2026-18871IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.3…7.3
- CVE-2026-18872IBM Financial Transaction Manager (FTM) for RedHat OpenShift…9.3
- CVE-2026-18874A flaw was found in volsync-addon-controller. This vulnerabi…6.2
Are you affected by CVE-2026-18860?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
