Rapid7CVE-2026-18636
Rapid7 Velociraptor: authentication bypass
Medium6.8CVE-2026-18636 · Published Aug 11, 2026 · updated Aug 28, 2026
The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users from reading sensitive files or accessing other orgs, the requested path is prefix checked against a list of denied prefixes. This prefix check can be bypassed allowing a user to access usually denied files. If the user has read permission in the ROOT org, this allows access to other orgs, in which the user may not have permission.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Velociraptor Product | < 0.77.2 | 0.77.2 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-288
More Rapid7 advisories
All Rapid7| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 11 | Rapid7 Velociraptor: null pointer dereference | Medium6.5 | 0.77.2 |
| Aug 11 | Rapid7 Velociraptor: authentication bypass by spoofing | High7.3 | 0.77.2 |
| Aug 11 | Rapid7 Velociraptor: path traversal | High7.1 | 0.77.2 |
| Aug 11 | Rapid7 Velociraptor: improper authorization | High7.2 | 0.77.2 |
| Aug 11 | Rapid7 Velociraptor: improper permission handling | High8.7 | 0.77.2 |
| Aug 11 | Rapid7 Velociraptor: denial of service | Medium6.2 | 0.77.2 |