PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-18860 Rapid7 CVE debrief

CVE-2026-18860 is a critical vulnerability in Velociraptor that allows administrators in child organizations to delete other organizations due to incorrect permission checks. This issue arises from Velociraptor's incorrect verification of the ORG_ADMIN permission within the calling organization instead of the ROOT organization. As a result, administrators in child organizations that are not also administrators in the ROOT organization can escalate their privileges and delete other organizations, potentially disrupting multi-tenant deployments. To address this vulnerability, organizations using Velociraptor must verify their organization configurations and user permissions to prevent unauthorized organization deletion. This includes reviewing organization structures, user roles, and permission settings. Additionally, they should monitor organization deletion activities and implement compensating controls for organization management where necessary. Security teams and vulnerability management teams should prioritize verifying and securing Velociraptor deployments to mitigate potential impacts from this vulnerability.

Vendor
Rapid7
Product
Velociraptor
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-11
Original CVE updated
2026-08-28
Advisory published
2026-08-11
Advisory updated
2026-08-28

Who should care

Organizations using Velociraptor with multi-tenant deployments, specifically those with child orgs and administrators, should verify their org configurations and user permissions to prevent unauthorized org deletion. This includes reviewing org structures, user roles, and permission settings. Additionally, they should monitor org deletion activities and implement compensating controls for org management where necessary. Security teams and vulnerability management teams should prioritize verifying and securing Velociraptor deployments to mitigate potential impacts from this vulnerability.

Technical summary

CVE-2026-18860 allows an administrator in a child org, which is not also an administrator in the ROOT org, to delete other orgs due to incorrect permission checks in Velociraptor. The issue arises from Velociraptor's incorrect checking of the ORG_ADMIN permission of callers within the calling ORG instead of the ROOT org. This incorrect permission check enables child org administrators to escalate their privileges and delete other orgs, potentially disrupting multi-tenant deployments. Organizations using Velociraptor should verify their org configurations and user permissions to prevent unauthorized org deletion.

Defensive priority

CVE-2026-18860 allows an administrator in a child org to delete other orgs due to incorrect permission checks. Organizations using Velociraptor should verify their org configurations and user permissions.

Recommended defensive actions

  • Verify org configurations and user permissions in Velociraptor deployments
  • Restrict ORG_ADMIN permissions to necessary personnel
  • Monitor org deletion activities
  • Implement compensating controls for org management
  • Review org structures and user roles
  • Conduct regular security audits for Velociraptor deployments
  • Track changes to org configurations and user permissions

Evidence notes

The CVE-2026-18860 issue results from Velociraptor's incorrect checking of the ORG_ADMIN permission. Org admins of child orgs can add this permission to their ACL token within their own org, allowing them to delete other orgs. This highlights the importance of closely managing org configurations and user permissions in Velociraptor deployments. To verify the affected scope, defenders should review org structures, user roles, and permission settings. They should also monitor org deletion activities and implement compensating controls for org management where necessary.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-18860 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-18860

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-18860 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18860

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.