PT-2026-47541 · Rapid7 · Velociraptor

·

CVE-2026-8795

·

Published

2026-06-09

·

Updated

2026-06-09

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rapid7 Velociraptor versions prior to 0.76.6
Description A YAML injection issue exists in the Windows.Collectors.Remapping artifact. The hostname field within the client info.json file of a collection ZIP is inserted into a YAML template using Go's text/template without proper escaping. An attacker can use literal double quotes and newlines in the hostname variable to break the YAML quoted string and inject a new mount remapping entry. If an analyst applies the resulting remapping file using the --remap flag, arbitrary VQL (Velociraptor Query Language) executes on the machine with NullACLManager, granting all permissions and bypassing the sandbox.
Recommendations Update to version 0.76.6 or later.

Fix

Special Elements Injection

Code Injection

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8795

Affected Products

Velociraptor