Artifact Overwrite Vulnerability in Velociraptor by Velocidex
CVE-2026-19200

8.9HIGH

Key Information:

Vendor

Rapid7

Vendor
CVE Published:
24 August 2026

What is CVE-2026-19200?

The Velociraptor verify() function, part of the VQL, is designed to check artifacts for syntax and other issues. An implementation issue allows unauthorized users to overwrite existing artifacts by leveraging the global artifact repository. This can occur even if the user possesses just the NOTEBOOK_EDIT permission, typically held by users in analyst roles. As a result, attackers can exploit this misconfiguration to manipulate critical artifacts, leading to potential data integrity and security issues within the system.

Affected Version(s)

Velociraptor Linux 0 < 0.77.2

References

CVSS V3.1

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yuval Miller and Leon Kayaliev
.