Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-19583: Velociraptor lets users run protected commands without proper rights

CVE-2026-19583 · published 12 days ago
Summary

Velociraptor’s monitoring feature can be used to start actions that should require special permission, such as running any command on a computer. This means a user who can set up monitoring can also run dangerous commands, potentially compromising the system. Apply the latest software update and restrict monitoring‑setup rights to trusted administrators only.

What to do
  • Update rapid7 velociraptor to version 0.77.2 or later.
Affected software
VendorProductAffected versions
rapid7 velociraptor < 0.77.2
Original advisory text
Velociraptor Required Permissions bypass by using client monitoring queries
Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. However, no such check was implemented for client monitoring artifacts. Additionally there was no requirement that client monitoring artifacts carry the CLIENT_EVENTS type. This allows any user who can schedule client monitoring artifacts to also schedule otherwise restricted artifacts (such as Linux.Sys.BashShell).
Severity
9.9 Critical
CVSS 3.1: 9.9 (NVD)
Exploitation
EPSS <1%
Type
CWE-732Incorrect Permission Assignment for Critical Resource
Timeline
Published10 Sep 2026
Updated21 Sep 2026
First seen10 Sep 2026
Sources
CVE-2026-19583 · MITRE
Track software like this
Free during beta