What is CVE-2026-18860?
CVE-2026-18860 affects Velociraptor's multi-tenant "Orgs" feature due to improper permission validation. It may allow users to perform administrative actions on child orgs without the required ORG_ADMIN permission. Affected deployments should apply official patches and review multi-tenant configurations immediately.
Azərbaycanca: CVE-2026-18860 zəifliyi Velociraptor platformasında "Orgs" çox-tenent funksiyasında icazə yoxlamasının düzgün aparılmaması ilə bağlıdır. Bu, istifadəçilərə ORG_ADMIN icazəsi olmadan child org-lar üzərində inzibati əməliyyatlar etməyə imkan verə bilər. Təsirə məruz qalan sistemlərdə dərhal rəsmi yamaq tətbiq edilməli və çox-tenent konfiqurasiyası nəzərdən keçirilməlidir.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: Velociraptor
FAQ2
Which feature of the Velociraptor platform is affected by CVE-2026-18860?
This vulnerability is related to improper permission validation in the platform's multi-tenant 'Orgs' feature.
What can a user do by exploiting CVE-2026-18860?
A user may perform administrative actions on child orgs without the required ORG_ADMIN permission.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.