CVE-2026-19583
Velociraptor has a flaw that lets users schedule powerful artifacts without proper permission checks. This can let an attacker run arbitrary commands on endpoints. The issue is critical because it bypasses normal security controls.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
All users of Velociraptor who have permission to schedule client monitoring artifacts, regardless of product version, are potentially affected.
Real-world impact
An attacker who can schedule client monitoring artifacts can also schedule restricted artifacts such as Linux.Sys.BashShell, giving them the ability to execute arbitrary commands on the target system.
Why this severity
The CVSS score of 9.9 reflects that the vulnerability is network reachable, low effort, requires low privilege, no user interaction, and can compromise confidentiality and integrity. The vector shows that an attacker can exploit it remotely with minimal effort and gain high confidentiality and integrity impact.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources