Artifact Overwrite Vulnerability in Velociraptor by Velocidex
CVE-2026-19200
8.9HIGH
What is CVE-2026-19200?
The Velociraptor verify() function, part of the VQL, is designed to check artifacts for syntax and other issues. An implementation issue allows unauthorized users to overwrite existing artifacts by leveraging the global artifact repository. This can occur even if the user possesses just the NOTEBOOK_EDIT permission, typically held by users in analyst roles. As a result, attackers can exploit this misconfiguration to manipulate critical artifacts, leading to potential data integrity and security issues within the system.
Affected Version(s)
Velociraptor Linux 0 < 0.77.2
