Skip to content
Rapid7CVE-2026-64954

Rapid7 Velociraptor: missing authorization

High8.2CVE-2026-64954 · Published Aug 12, 2026 · updated Aug 28, 2026

Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the authorization provider. This allows a user who can run arbitrary VQL (usually with the "analyst" role) to launch new collections (usually requires the "investigator" role). This vulnerability is an escalation from an analyst to investigator role.

Rapid7 advisory

Affected versions

PackageAffectedFixed in
Velociraptor
Product
< 0.77.20.77.2
Details and references

More Rapid7 advisories

All Rapid7
Advisory
A rogue Velociraptor client can upload a malformed sparse file such
Low3.5Aug 12
Rapid7 Velociraptor: improper authorization
Medium6.5Aug 12
Rapid7 Velociraptor: CSV injection
Medium6.1Aug 12
Rapid7 Velociraptor: missing authorization
Medium6.5Aug 12
Rapid7 Velociraptor: null pointer dereference
Medium6.5Aug 11
Rapid7 Velociraptor: authentication bypass by spoofing
High7.3Aug 11

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.