Rapid7CVE-2026-64954
Rapid7 Velociraptor: missing authorization
High8.2CVE-2026-64954 · Published Aug 12, 2026 · updated Aug 28, 2026
Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the authorization provider. This allows a user who can run arbitrary VQL (usually with the "analyst" role) to launch new collections (usually requires the "investigator" role). This vulnerability is an escalation from an analyst to investigator role.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Velociraptor Product | < 0.77.2 | 0.77.2 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-862
More Rapid7 advisories
All Rapid7| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 12 | A rogue Velociraptor client can upload a malformed sparse file such | Low3.5 | 0.77.2 |
| Aug 12 | Rapid7 Velociraptor: improper authorization | Medium6.5 | 0.77.2 |
| Aug 12 | Rapid7 Velociraptor: CSV injection | Medium6.1 | 0.77.2 |
| Aug 12 | Rapid7 Velociraptor: missing authorization | Medium6.5 | 0.77.2 |
| Aug 11 | Rapid7 Velociraptor: null pointer dereference | Medium6.5 | 0.77.2 |
| Aug 11 | Rapid7 Velociraptor: authentication bypass by spoofing | High7.3 | 0.77.2 |