THREAT OPS › Threat News › [NVD] CVE-2026-18860 (HIGH 8.7) — Velociraptor allows multi-tenant deployments named "Orgs".
By default Velociraptor, uses the ROOT org, but users can create child orgs for other tenants within the same deployment.
Users can have different permissions in each org. To manage Orgs, Velociraptor usually examines t
[NVD] CVE-2026-18860 (HIGH 8.7) — Velociraptor allows multi-tenant deployments named "Orgs". By default Velociraptor, uses the ROOT org, but users can create child orgs for other tenants within the same deployment. Users can have different permissions in each org. To manage Orgs, Velociraptor usually examines t
CVE-2026-18860 CVSS: 8.7 HIGH Published: 2026-08-11T15:17:28.887
Velociraptor allows multi-tenant deployments named "Orgs".
By default Velociraptor, uses the ROOT org, but users can create child orgs for other tenants within the same deployment.
Users can have different permissions in each org. To manage Orgs, Velociraptor usually examines the ORG_ADMIN permission on the ROOT org.
This issue r
Indicators of compromise
- CVE-2026-18860cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18860