Permission Misconfiguration in Velociraptor Allowing Unauthorized Deletion of Hunts
CVE-2026-64952
6.5MEDIUM
What is CVE-2026-64952?
A vulnerability in Velociraptor's hunt_delete() VQL function exposes a flaw in the permission checks, allowing users with the COLLECT_CLIENT role, typically assigned to investigators, to execute deletion of hunts. This operation should be restricted to users with the DELETE_RESULTS permission, typically held by administrators. This misconfiguration opens the door for unauthorized users to manipulate critical data, thereby compromising the integrity of the system.
Affected Version(s)
Velociraptor 0 < 0.77.2
