Unauthorized Role Escalation in Velociraptor by Velocidex
CVE-2026-64954

8.2HIGH

Key Information:

Vendor

Rapid7

Vendor
CVE Published:
12 August 2026

What is CVE-2026-64954?

The Velociraptor platform has a security concern where users with the 'analyst' role can execute arbitrary VQL queries that reset the authorization provider. By doing so, these users can schedule new collections, a privilege typically reserved for users with the 'investigator' role. This vulnerability bypasses permission enforcement for the COLLECT_CLIENT privilege, enabling unauthorized role escalation and potentially exposing sensitive data and actions to lower-privileged users.

Affected Version(s)

Velociraptor Linux 0 < 0.77.2

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Reported independently by Tristan Madani (Talence Security)
Reported independently by Yuval Miller
Reported independently by Leon Kayaliev
.