Unauthorized Role Escalation in Velociraptor by Velocidex
CVE-2026-64954
8.2HIGH
What is CVE-2026-64954?
The Velociraptor platform has a security concern where users with the 'analyst' role can execute arbitrary VQL queries that reset the authorization provider. By doing so, these users can schedule new collections, a privilege typically reserved for users with the 'investigator' role. This vulnerability bypasses permission enforcement for the COLLECT_CLIENT privilege, enabling unauthorized role escalation and potentially exposing sensitive data and actions to lower-privileged users.
Affected Version(s)
Velociraptor Linux 0 < 0.77.2
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Reported independently by Tristan Madani (Talence Security)
Reported independently by Yuval Miller
Reported independently by Leon Kayaliev
