VFSGetBuffer Vulnerability in Velociraptor API Affects Sensitive File Access
CVE-2026-18636

6.8MEDIUM

Key Information:

Vendor

Rapid7

Vendor
CVE Published:
11 August 2026

What is CVE-2026-18636?

The Velociraptor gRPC API contains a vulnerability in the VFSGetBuffer endpoint that enables users to read files from the datastore. This endpoint employs a prefix check to restrict access to sensitive files and prevent unauthorized access to other organization's data. However, this prefix check can be bypassed, which potentially grants users who possess read permissions in the ROOT organization access to files they are typically denied from across other organizations. This flaw could lead to unintended exposure of sensitive data.

Affected Version(s)

Velociraptor 0 < 0.77.2

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Itay Vardi
.