Rapid7 Velociraptor: insecure permissions
Critical9.9CVE-2026-19583 · Published Sep 10, 2026 · updated Sep 11, 2026
Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. However, no such check was implemented for client monitoring artifacts. Additionally there was no requirement that client monitoring artifacts carry the CLIENT_EVENTS type. This allows any user who can schedule client monitoring artifacts to also schedule otherwise restricted artifacts (such as Linux.Sys.BashShell).
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Velociraptor Product | < 0.77.2 | 0.77.2 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-732
More Rapid7 advisories
All Rapid7| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 24 | Rapid7 Insight Agent: code execution | High7.8 | No fix yet |
| Sep 24 | Velociraptor contains a deadlock condition | Medium6.5 | 0.77.2 |
| Sep 24 | Rapid7 Velociraptor: improper input validation | Low3.6 | 0.77.3 |
| Sep 24 | Velociraptor stores the compiled VQL in the hunt object internally to avoid... | Critical9.9 | 0.77.2 |
| Sep 10 | Rapid7 Velociraptor: code injection | High7.7 | 0.77.2 |
| Aug 27 | A logic vulnerability | Medium5.1 | 6.5.2 |