Rapid7CVE-2026-19584
Rapid7 Velociraptor: code injection
High7.7CVE-2026-19584 · Published Sep 10, 2026 · updated Sep 11, 2026
Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a malicious user with NOTEBOOK_EDITOR permission to plant a VQL query which will be evaluated at elevated permissions if the notebook's backup is subsequently restored.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Velociraptor Product | < 0.77.2 | 0.77.2 |
Details and references
More Rapid7 advisories
All Rapid7| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 24 | Rapid7 Insight Agent: code execution | High7.8 | No fix yet |
| Sep 24 | Velociraptor contains a deadlock condition | Medium6.5 | 0.77.2 |
| Sep 24 | Rapid7 Velociraptor: improper input validation | Low3.6 | 0.77.3 |
| Sep 24 | Velociraptor stores the compiled VQL in the hunt object internally to avoid... | Critical9.9 | 0.77.2 |
| Sep 10 | Rapid7 Velociraptor: insecure permissions | Critical9.9 | 0.77.2 |
| Aug 27 | A logic vulnerability | Medium5.1 | 6.5.2 |