Permission Misconfiguration in Velociraptor Allowing Unauthorized Deletion of Hunts
CVE-2026-64952

6.5MEDIUM

Key Information:

Vendor

Rapid7

Vendor
CVE Published:
12 August 2026

What is CVE-2026-64952?

A vulnerability in Velociraptor's hunt_delete() VQL function exposes a flaw in the permission checks, allowing users with the COLLECT_CLIENT role, typically assigned to investigators, to execute deletion of hunts. This operation should be restricted to users with the DELETE_RESULTS permission, typically held by administrators. This misconfiguration opens the door for unauthorized users to manipulate critical data, thereby compromising the integrity of the system.

Affected Version(s)

Velociraptor 0 < 0.77.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tristan Madani (Talence Security)
.