4.1
CVE-2026-18348
- EPSS 0.25%
- Veröffentlicht 11.08.2026 05:37:11
- Zuletzt bearbeitet 11.08.2026 15:17:28
- CVE-Watchlists
- Unerledigt
Velociraptor NETWORK ACL bypass via upload_azure / upload_sftp / upload_smb VQL plugins
Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst-role user can initiate attacker-controlled outbound network connections from the Velociraptor server, bypassing the NETWORK ACL permission boundary. This enables internal network reconnaissance via port oracle and potential data exfiltration to external endpoints.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRapid7
≫
Produkt
Velociraptor
Default Statusunaffected
Version
0
Version <
0.77.2
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.159 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Rapid7 | 4.1 | 2.3 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
http://docs.velociraptor.app/announcements/advisories/cve-2026-18348/
https://github.com/Velocidex/velociraptor/commit/48824fb51a2bdba832abc281e719ecbed74736df