Unauthorized Outbound Connection Vulnerability in Velociraptor by Velocidex
CVE-2026-18348

4.1MEDIUM

Key Information:

Vendor

Rapid7

Vendor
CVE Published:
11 August 2026

What is CVE-2026-18348?

A significant security flaw in Velociraptor's upload plugins allows authenticated users with analyst roles to bypass authorization checks, leading to unauthorized outbound network connections. This vulnerability enables potential attackers to conduct internal network reconnaissance and facilitates data exfiltration to external systems, presenting substantial risks to data integrity and confidentiality.

Affected Version(s)

Velociraptor Linux 0 < 0.77.2

References

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Hamad Alghamdi
.