Remote Code Execution Risk in Velociraptor Due to Insufficient Access Control
CVE-2026-19584
7.7HIGH
What is CVE-2026-19584?
Velociraptor's default daily backup feature for notebook creation lacks adequate access control checks during restoration. This design flaw enables a user with NOTEBOOK_EDITOR permission to inject a potentially harmful VQL query. If an attacker restores the compromised backup, the query can be executed with elevated privileges, posing a significant security risk. Organizations using Velociraptor should review their backup practices and apply the necessary patches to mitigate this vulnerability effectively.
Affected Version(s)
Velociraptor Linux 0 < 0.77.2
