Vulnerability in Velociraptor Client Monitoring Leading to Unauthorized Command Execution
CVE-2026-19583
9.9CRITICAL
What is CVE-2026-19583?
Velociraptor's client monitoring capabilities suffer from a critical permissions oversight. While certain sensitive artifacts, like Linux.Sys.BashShell, are gated by specific permissions such as EXECVE, client monitoring artifacts lack similar constraints. This oversight allows users with the ability to schedule client monitoring artifacts unrestricted access to execute sensitive commands on endpoints, posing a significant security risk. The absence of type checks for client monitoring artifacts enables potential exploitation, making it crucial for all users to update and secure their systems against this vulnerability.
Affected Version(s)
Velociraptor Linux 0 < 0.77.2
