Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-19072: Velociraptor investigator can gain admin rights

CVE-2026-19072 · published 5 days ago
Summary

In Velociraptor, a user with the investigator role can change an internal setting that lets them run any query on the server, bypassing normal permission checks. This means they could perform actions reserved for administrators. Restrict or remove the ability to set the compiled_collector_args field via the API, and review investigator accounts for any misuse.

What to do
  • Update rapid7 velociraptor to version 0.77.2 or later.
Affected software
VendorProductAffected versions
rapid7 velociraptor < 0.77.2
Original advisory text
Velociraptor Investigator reaches SuperUser via hunt EffectivePrincipal
Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each endpoint in the hunt. Although the field "compiled_collector_args" is an internal field, Velociraptor allowed the field to be set from a user API call. This allows another user who can schedule a hunt (minimal role of "investigator" ) to set the compiled VQL statements for the hunt bypassing any ACL checks that would normally be applied.




This flaw can then be escalated to allow the "investigator" user to run arbitrary VQL statements as an administrator user on the Velociraptor server.
Severity
9.9 Critical
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS <1%
Type
CWE-1269Product Released in Non-Release Configuration
CWE-164Improper Neutralization of Internal Special Elements
Timeline
Published24 Sep 2026
Updated29 Sep 2026
First seen24 Sep 2026
Sources
CVE-2026-19072 · MITRE
Track software like this
Free during beta