PT-2026-97792 · Unknown · Velociraptor
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Velociraptor (affected versions not specified)
Description
Velociraptor stores compiled VQL (Velociraptor Query Language) within the hunt object to prevent redundant recompilation for every endpoint. A flaw exists where the internal field
compiled collector args can be modified via a user API call. This allows a user with the investigator role to define compiled VQL statements for a hunt, bypassing standard Access Control List (ACL) checks. This issue can be escalated to enable an investigator to execute arbitrary VQL statements with administrator privileges on the server.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Velociraptor