Skip to content
Rapid7CVE-2026-19583

Rapid7 Velociraptor: insecure permissions

Critical9.9CVE-2026-19583 · Published Sep 10, 2026 · updated Sep 11, 2026

Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. However, no such check was implemented for client monitoring artifacts. Additionally there was no requirement that client monitoring artifacts carry the CLIENT_EVENTS type. This allows any user who can schedule client monitoring artifacts to also schedule otherwise restricted artifacts (such as Linux.Sys.BashShell).

Rapid7 advisory

Affected versions

PackageAffectedFixed in
Velociraptor
Product
< 0.77.20.77.2
Details and references

More Rapid7 advisories

All Rapid7
Advisory
Rapid7 Insight Agent: code execution
High7.8Sep 24
Velociraptor contains a deadlock condition
Medium6.5Sep 24
Rapid7 Velociraptor: improper input validation
Low3.6Sep 24
Velociraptor stores the compiled VQL in the hunt object internally to avoid...
Critical9.9Sep 24
Rapid7 Velociraptor: code injection
High7.7Sep 10
A logic vulnerability
Medium5.1Aug 27

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.