๐Ÿ” CVE Alert

CVE-2026-18348

MEDIUM 4.1

Velociraptor NETWORK ACL bypass via upload_azure / upload_sftp / upload_smb VQL plugins

CVSS Score
4.1
EPSS Score
0.0%
EPSS Percentile
0th

Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst-role user can initiate attacker-controlled outbound network connections from the Velociraptor server, bypassing the NETWORK ACL permission boundary. This enables internal network reconnaissance via port oracle and potential data exfiltration to external endpoints.

CWE CWE-863
Vendor rapid7
Product velociraptor
Published Aug 11, 2026
Stay Ahead of the Next One

Get instant alerts for rapid7 velociraptor

Be the first to know when new medium vulnerabilities affecting rapid7 velociraptor are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

Rapid7 / Velociraptor
0 < 0.77.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
docs.velociraptor.app: http://docs.velociraptor.app/announcements/advisories/cve-2026-18348/ github.com: https://github.com/Velocidex/velociraptor/commit/48824fb51a2bdba832abc281e719ecbed74736df

Credits

Hamad Alghamdi