Rapid7CVE-2026-18638
Rapid7 Velociraptor: null pointer dereference
Medium6.5CVE-2026-18638 · Published Aug 11, 2026 · updated Aug 28, 2026
Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server process with a single request, by calling SetPassword with a username that does not exist.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Velociraptor Product | < 0.77.2 | 0.77.2 |
Details and references
More Rapid7 advisories
All Rapid7| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 11 | Rapid7 Velociraptor: authentication bypass by spoofing | High7.3 | 0.77.2 |
| Aug 11 | Rapid7 Velociraptor: path traversal | High7.1 | 0.77.2 |
| Aug 11 | Rapid7 Velociraptor: improper authorization | High7.2 | 0.77.2 |
| Aug 11 | Rapid7 Velociraptor: authentication bypass | Medium6.8 | 0.77.2 |
| Aug 11 | Rapid7 Velociraptor: improper permission handling | High8.7 | 0.77.2 |
| Aug 11 | Rapid7 Velociraptor: denial of service | Medium6.2 | 0.77.2 |