Skip to content
Rapid7CVE-2026-19584

Rapid7 Velociraptor: code injection

High7.7CVE-2026-19584 · Published Sep 10, 2026 · updated Sep 11, 2026

Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a malicious user with NOTEBOOK_EDITOR permission to plant a VQL query which will be evaluated at elevated permissions if the notebook's backup is subsequently restored.

Rapid7 advisory

Affected versions

PackageAffectedFixed in
Velociraptor
Product
< 0.77.20.77.2
Details and references

More Rapid7 advisories

All Rapid7
Advisory
Rapid7 Insight Agent: code execution
High7.8Sep 24
Velociraptor contains a deadlock condition
Medium6.5Sep 24
Rapid7 Velociraptor: improper input validation
Low3.6Sep 24
Velociraptor stores the compiled VQL in the hunt object internally to avoid...
Critical9.9Sep 24
Rapid7 Velociraptor: insecure permissions
Critical9.9Sep 10
A logic vulnerability
Medium5.1Aug 27

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.