PT-2026-97792 · Unknown · Velociraptor

·

CVE-2026-19072

·

Published

2026-09-24

·

Updated

2026-09-25

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Velociraptor (affected versions not specified)
Description Velociraptor stores compiled VQL (Velociraptor Query Language) within the hunt object to prevent redundant recompilation for every endpoint. A flaw exists where the internal field compiled collector args can be modified via a user API call. This allows a user with the investigator role to define compiled VQL statements for a hunt, bypassing standard Access Control List (ACL) checks. This issue can be escalated to enable an investigator to execute arbitrary VQL statements with administrator privileges on the server.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19072

Affected Products

Velociraptor