PT-2026-106061 · Unknown · Velociraptor

·

CVE-2026-78413

·

Published

2026-10-05

·

Updated

2026-10-05

CVSS v3.1

5.5

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Velociraptor (affected versions not specified)
Description Velociraptor uses Artifacts to package VQL queries for collection from endpoints, which typically execute with elevated permissions. To restrict dangerous operations, certain artifacts require high-level permissions such as EXECVE. The Windows.Sysinternals.SysmonLogForward monitoring artifact, designed to forward sysmon events to the server, allows users to specify an arbitrary binary path as a parameter. Because it fails to enforce the necessary additional permissions, users with COLLECT CLIENT permissions (typically assigned to the Investigator role) can execute an arbitrary binary program on the endpoint instead of the intended sysmon binary.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78413

Affected Products

Velociraptor