Impersonation Flaw in Velociraptor Software
CVE-2026-18635
7.2HIGH
What is CVE-2026-18635?
Velociraptor's query() plugin enables execution of VQL queries in different organizational or user contexts. However, in versions earlier than 0.77.2, it mistakenly evaluates the IMPERSONATE permission against the caller's organization, not the target one. This misconfiguration allows an administrator in one organization to impersonate users from another organization without having the proper permission, potentially leading to unauthorized access and data manipulation.
Affected Version(s)
Velociraptor 0 < 0.77.2
