Unauthorized Server Termination Vulnerability in Velociraptor by Velociraptor Team
CVE-2026-18638
6.5MEDIUM
What is CVE-2026-18638?
An issue exists in Velociraptor where any authenticated user, even those with minimal permissions such as 'reader,' can exploit a flaw in the SetPassword method. By sending a request with a nonexistent username, these users can unintentionally or maliciously terminate the entire server process. This poses a significant risk to server stability and availability.
Affected Version(s)
Velociraptor 0 < 0.77.2
