Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-19072— Velociraptor Investigator reaches SuperUser via hunt EffectivePrincipal

Quick assessment

Affected
Rapid7 Velociraptor
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Velociraptor 在内部 hunts 对象中存储编译后的 VQL 语句,以便避免为 hunt 中的每个端点重复编译工件。尽管 "compiled_collector_args" 字段是一个内部字段,但 Velociraptor 允许通过用户 API 调用来设置该字段。这使得其他具有调度 hunt 权限的用户(最低角色为 "investigator")可以绕过正常应用的访问控制列表(ACL)检查,为 hunt 设置编译后的 VQL 语句。 该漏洞可进一步被利用,使 "investigator" 用户能够在 V

CVSS 9.9 · Critical EPSS 0.40% · P31
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-19072

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Velociraptor Investigator reaches SuperUser via hunt EffectivePrincipal
Source: CVE Program / CVE List V5
Vulnerability Description
Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each endpoint in the hunt. Although the field "compiled_collector_args" is an internal field, Velociraptor allowed the field to be set from a user API call. This allows another user who can schedule a hunt (minimal role of "investigator" ) to set the compiled VQL statements for the hunt bypassing any ACL checks that would normally be applied. This flaw can then be escalated to allow the "investigator" user to run arbitrary VQL statements as an administrator user on the Velociraptor server.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1269
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Rapid7 Velociraptor 0 ~ 0.77.2 -

II. Public POCs for CVE-2026-19072

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-19072

请登录查看更多情报信息。

Other References for CVE-2026-19072 (1)

Same Patch Batch · Rapid7 · 2026-09-24 · 4 CVEs total

CVE-2026-89325 7.8 HIGH Rapid7 Insight Agent: Uncontrolled search path element in InsightVM assessment content lea
CVE-2026-77798 6.5 MEDIUM Velociraptor Authenticated Denial of Service
CVE-2026-77797 3.6 LOW Velociraptor Prefetch parser out of bounds

IV. Related Vulnerabilities

V. Comments for CVE-2026-19072

No comments yet


Leave a comment