VQL Statement Manipulation in Velociraptor by Investigation Roles
CVE-2026-19072
9.9CRITICAL
What is CVE-2026-19072?
A vulnerability in Velociraptor enables an investigator role user to manipulate compiled VQL statements due to improper access control on the 'compiled_collector_args' field. This flaw allows unauthorized users to set VQL for hunts, potentially allowing them to execute arbitrary statements with administrative privileges on the Velociraptor server, thereby elevating their permissions and compromising system integrity.
Affected Version(s)
Velociraptor 0 < 0.77.2
