Rapid7CVE-2026-19200
Rapid7 Velociraptor: code injection
High8.9CVE-2026-19200 · Published Aug 24, 2026 · updated Aug 28, 2026
The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other issues. Due to an implementation fault in this VQL function, the global artifact repository is used which allows callers to overwrite existing artifacts without the required permissions. The attacker need only have the NOTEBOOK_EDIT permission (e.g. an analyst role) to be able to call this function.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Velociraptor Product | < 0.77.2 | 0.77.2 |
Details and references
More Rapid7 advisories
All Rapid7| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 27 | A logic vulnerability | Medium5.1 | 6.5.2 |
| Aug 18 | Rapid7 Velociraptor: cross-site scripting | High8.1 | 0.77.2 |
| Aug 12 | A rogue Velociraptor client can upload a malformed sparse file such | Low3.5 | 0.77.2 |
| Aug 12 | Rapid7 Velociraptor: improper authorization | Medium6.5 | 0.77.2 |
| Aug 12 | Rapid7 Velociraptor: CSV injection | Medium6.1 | 0.77.2 |
| Aug 12 | Rapid7 Velociraptor: missing authorization | Medium6.5 | 0.77.2 |