CVE-2026-78413
- EPSS 0.16%
- Veröffentlicht 05.10.2026 17:48:03
- Zuletzt bearbeitet 06.10.2026 15:09:20
Velociraptor allows collection of VQL queries packaged into Artifacts from endpoints. These artifacts can be used to do anything and usually run with elevated permissions. To limit access to some dangerous artifact, Velociraptor allows for those to r...
CVE-2026-78411
- EPSS 0.17%
- Veröffentlicht 05.10.2026 17:19:26
- Zuletzt bearbeitet 06.10.2026 15:09:20
Velociraptor's SetClientMetadata used the wrong permission check to enforce setting metadata on the server. This allows a user with LABEL_CLIENTS permission to update the server metadata. Server metadata is often used to store site wide configuratio...
CVE-2026-78412
- EPSS 0.22%
- Veröffentlicht 05.10.2026 16:51:34
- Zuletzt bearbeitet 06.10.2026 15:09:20
Velociraptor's WatchEvent gRPC API can specify the OrgId of the org from which events should be streamed. The server checks the API permissions against the caller's Org instead of the requested Org. This allows a user with API access in one org to re...
CVE-2026-77798
- EPSS 0.2%
- Veröffentlicht 24.09.2026 13:50:40
- Zuletzt bearbeitet 24.09.2026 21:00:46
Velociraptor contains a deadlock condition that may be triggered by authenticated users. The issue stems from a lock management bug in the user management module.
CVE-2026-77797
- EPSS 0.11%
- Veröffentlicht 24.09.2026 13:49:41
- Zuletzt bearbeitet 24.09.2026 21:00:46
Velociraptor's prefetch library contains an out of bound vulnerability which may cause a crash when parsing certain malformed prefetch files.
CVE-2026-19072
- EPSS 0.4%
- Veröffentlicht 24.09.2026 12:52:51
- Zuletzt bearbeitet 25.09.2026 04:17:34
Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each endpoint in the hunt. Although the field "compiled_collector_args" is an internal field, Velociraptor allowed the field to be set f...
CVE-2026-19584
- EPSS 0.19%
- Veröffentlicht 10.09.2026 03:00:00
- Zuletzt bearbeitet 11.09.2026 04:17:34
Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a malicious user wi...
CVE-2026-19583
- EPSS 0.6%
- Veröffentlicht 10.09.2026 02:58:11
- Zuletzt bearbeitet 11.09.2026 04:17:24
Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. However, no such ...
CVE-2026-19200
- EPSS 0.23%
- Veröffentlicht 24.08.2026 04:16:46
- Zuletzt bearbeitet 28.08.2026 21:17:10
The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other issues. Due to an implementation fault in this VQL function, the global artifact repository is used which allows callers to overwrite existing artifacts...
CVE-2026-15371
- EPSS 0.21%
- Veröffentlicht 18.08.2026 06:52:28
- Zuletzt bearbeitet 28.08.2026 21:17:10
Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the cell value and forms a URL which can be clicked in the GUI.The code does not limit the schemes allowed in this URL , allowing an attacker to specify ...