CVE-2026-19200
Velociraptor Analyst overwrites live built-in artifacts through verify()
CVSS Score
8.9
EPSS Score
0.0%
EPSS Percentile
0th
The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other issues. Due to an implementation fault in this VQL function, the global artifact repository is used which allows callers to overwrite existing artifacts without the required permissions.ย The attacker need only have the NOTEBOOK_EDIT permission (e.g. an analyst role) to be able to call this function.
| CWE | CWE-862 CWE-94 |
| Vendor | rapid7 |
| Product | velociraptor |
| Published | Aug 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for rapid7 velociraptor
Be the first to know when new high vulnerabilities affecting rapid7 velociraptor are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
Low
Affected Versions
Rapid7 / Velociraptor
0 < 0.77.2
References
Credits
Yuval Miller and Leon Kayaliev