PT-2026-70236 · Rapid7+1 · Velociraptor

·

CVE-2026-18640

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description The NewNotebook API fails to properly sanitize parameters, enabling an authenticated user with NOTEBOOK EDIT permissions to write notebook records outside the organization's data store directory. While the written file must use the .json.db extension, this flaw allows the overwriting of other metadata files, including ACL records and hunts, which can lead to significant data corruption.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18640

Affected Products

Velociraptor