THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-18860 (HIGH 8.7) — Velociraptor allows multi-tenant deployments named "Orgs". By default Velociraptor, uses the ROOT org, but users can create child orgs for other tenants within the same deployment. Users can have different permissions in each org. To manage Orgs, Velociraptor usually examines t

[NVD] CVE-2026-18860 (HIGH 8.7) — Velociraptor allows multi-tenant deployments named "Orgs". By default Velociraptor, uses the ROOT org, but users can create child orgs for other tenants within the same deployment. Users can have different permissions in each org. To manage Orgs, Velociraptor usually examines t

mednvdPublished 2026-08-11

CVE-2026-18860 CVSS: 8.7 HIGH Published: 2026-08-11T15:17:28.887

Velociraptor allows multi-tenant deployments named "Orgs".

By default Velociraptor, uses the ROOT org, but users can create child orgs for other tenants within the same deployment.

Users can have different permissions in each org. To manage Orgs, Velociraptor usually examines the ORG_ADMIN permission on the ROOT org.

This issue r

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18860