CVE-2026-17535
- EPSS 0.12%
- Veröffentlicht 11.08.2026 14:47:13
- Zuletzt bearbeitet 11.08.2026 20:17:36
Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by maliciously crafted NTFS images. Typically Velociraptor's NTFS parser is used on live NTFS filesystems, limiting the opportunity...
CVE-2026-18636
- EPSS 0.24%
- Veröffentlicht 11.08.2026 14:40:12
- Zuletzt bearbeitet 11.08.2026 20:17:36
The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users from reading sensitive files or accessing other orgs, the requested path is prefix checked against a list of denied prefixes. This p...
CVE-2026-18635
- EPSS 0.26%
- Veröffentlicht 11.08.2026 14:15:58
- Zuletzt bearbeitet 12.08.2026 19:17:30
Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able to run as a different user, the calling user needs to have the IMPERSONATE permission (usually only given to administrators). Velo...
CVE-2026-18972
- EPSS 0.33%
- Veröffentlicht 11.08.2026 12:30:52
- Zuletzt bearbeitet 11.08.2026 14:17:12
An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a user with low privileges to administrator.
CVE-2026-18348
- EPSS 0.25%
- Veröffentlicht 11.08.2026 05:37:11
- Zuletzt bearbeitet 11.08.2026 15:17:28
Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst-role user can initiate attacker-controlled outbound network connections from the Velociraptor server, bypassing the NETWORK ACL p...
CVE-2026-8795
- EPSS 0.15%
- Veröffentlicht 09.06.2026 01:04:21
- Zuletzt bearbeitet 23.07.2026 08:10:00
A YAML injection vulnerability exists in the Windows.Collectors.Remapping artifact of Rapid7 Velociraptor before version 0.76.6. The hostname field in client_info.json inside a collection ZIP is inserted into a YAML template via Go's text/template wi...
CVE-2026-6863
- EPSS 0.24%
- Veröffentlicht 06.05.2026 14:50:55
- Zuletzt bearbeitet 07.05.2026 14:56:04
Velociraptor versions prior to 0.76.4 contain a cross organization authorization bypass in the HTTP API. A user with only the reader role in the root organization (the lowest authenticated role, holding only READ_RESULTS permission ) can issue a sing...
CVE-2026-7573
- EPSS 0.26%
- Veröffentlicht 06.05.2026 03:15:59
- Zuletzt bearbeitet 24.07.2026 08:10:00
An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 allows any authenticated low-privilege user to retrieve the complete ACL policy (roles and permissions) for any user across all org...
CVE-2026-7572
- EPSS 0.14%
- Veröffentlicht 06.05.2026 03:15:58
- Zuletzt bearbeitet 24.07.2026 08:10:00
An off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions in Velocidex Velociraptor before version 0.76.5 on Windows and Linux allows a local attacker to cause a Denial of Service (DoS) via a process crash by providing ...
CVE-2026-6948
- EPSS 0.34%
- Veröffentlicht 04.05.2026 00:16:39
- Zuletzt bearbeitet 04.05.2026 15:22:52
Velociraptor versions prior to 0.76.4 contain a resource exhaustion vulnerability in the server's agent control channel. This allows a compromised or rogue Velociraptor client to crash the server via out-of-memory (OOM) by sending crafted messages...