Remote Code Execution Vulnerability in Velociraptor Monitoring Tool
CVE-2026-78413
5.5MEDIUM
What is CVE-2026-78413?
Velociraptor enables the collection of VQL queries through Artifacts from endpoints, which can execute with elevated permissions. The artifact known as Windows.Sysinternals.SysmonLogForward permits users to specify an arbitrary binary path. However, it fails to enforce strict permission checks, allowing users with COLLECT_CLIENT permissions, typically those in the 'Investigator' role, to execute unauthorized binaries instead of the intended Sysmon binary. To exploit this vulnerability, an attacker must already possess access to collect artifacts from the endpoint.
Affected Version(s)
Velociraptor Linux 0 < 0.77.3
