Vulnary
← back to the feed
Critical· 9.9

CVE-2026-19583

Velociraptor has a flaw that lets users schedule powerful artifacts without proper permission checks. This can let an attacker run arbitrary commands on endpoints. The issue is critical because it bypasses normal security controls.

publishedSep 10, 2026
last modifiedSep 11, 2026
sourcesNVD
severity · cvss
9.9
critical · how bad it is
exploitation · epss
<1%
47th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Oct 25, 2026

No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.

01

Who is affected

All users of Velociraptor who have permission to schedule client monitoring artifacts, regardless of product version, are potentially affected.

02

Real-world impact

An attacker who can schedule client monitoring artifacts can also schedule restricted artifacts such as Linux.Sys.BashShell, giving them the ability to execute arbitrary commands on the target system.

03

Why this severity

The CVSS score of 9.9 reflects that the vulnerability is network reachable, low effort, requires low privilege, no user interaction, and can compromise confidentiality and integrity. The vector shows that an attacker can exploit it remotely with minimal effort and gain high confidentiality and integrity impact.

04

What to do about it

no official fix yet

No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.

No fix documented in sources

05

Timeline

06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredLow
User interactionNone needed
ScopeChanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactLow
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
CVE-2026-19583: Velociraptor has a flaw that lets users schedule powerful artifacts wi · Vulnary