VQL Statement Manipulation in Velociraptor by Investigation Roles
CVE-2026-19072

9.9CRITICAL

Key Information:

Vendor

Rapid7

Vendor
CVE Published:
24 September 2026

What is CVE-2026-19072?

A vulnerability in Velociraptor enables an investigator role user to manipulate compiled VQL statements due to improper access control on the 'compiled_collector_args' field. This flaw allows unauthorized users to set VQL for hunts, potentially allowing them to execute arbitrary statements with administrative privileges on the Velociraptor server, thereby elevating their permissions and compromising system integrity.

Affected Version(s)

Velociraptor 0 < 0.77.2

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yuval Miller
Leon Kayaliev
.