Impersonation Flaw in Velociraptor Software
CVE-2026-18635

7.2HIGH

Key Information:

Vendor

Rapid7

Vendor
CVE Published:
11 August 2026

What is CVE-2026-18635?

Velociraptor's query() plugin enables execution of VQL queries in different organizational or user contexts. However, in versions earlier than 0.77.2, it mistakenly evaluates the IMPERSONATE permission against the caller's organization, not the target one. This misconfiguration allows an administrator in one organization to impersonate users from another organization without having the proper permission, potentially leading to unauthorized access and data manipulation.

Affected Version(s)

Velociraptor 0 < 0.77.2

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Itay Vardi
.