An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 allows any authenticated low-privilege user to retrieve the complete ACL policy (roles and permissions) for any user across all organizations by supplying targeted Name and Org parameters via a network request.
{
"nvd_published_at": "2026-05-06T03:15:59Z",
"cwe_ids": [
"CWE-639"
],
"github_reviewed_at": "2026-05-11T16:23:57Z",
"github_reviewed": true,
"severity": "MODERATE"
}