Remote Code Execution Vulnerability in Velociraptor Monitoring Tool
CVE-2026-78413

5.5MEDIUM

Key Information:

Vendor

Rapid7

Vendor
CVE Published:
5 October 2026

What is CVE-2026-78413?

Velociraptor enables the collection of VQL queries through Artifacts from endpoints, which can execute with elevated permissions. The artifact known as Windows.Sysinternals.SysmonLogForward permits users to specify an arbitrary binary path. However, it fails to enforce strict permission checks, allowing users with COLLECT_CLIENT permissions, typically those in the 'Investigator' role, to execute unauthorized binaries instead of the intended Sysmon binary. To exploit this vulnerability, an attacker must already possess access to collect artifacts from the endpoint.

Affected Version(s)

Velociraptor Linux 0 < 0.77.3

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yuval Miller
Leon Kayaliev
.