๐Ÿ” CVE Alert

CVE-2026-64954

HIGH 8.2

Velociraptor collect_client() Permissions Bypass

CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th

Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the authorization provider. This allows a user who can run arbitrary VQL (usually with the "analyst" role) to launch new collections (usually requires the "investigator" role). This vulnerability is an escalation from an analyst to investigator role.

CWE CWE-862
Vendor rapid7
Product velociraptor
Published Aug 12, 2026
Stay Ahead of the Next One

Get instant alerts for rapid7 velociraptor

Be the first to know when new high vulnerabilities affecting rapid7 velociraptor are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

Rapid7 / Velociraptor
0 < 0.77.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
docs.velociraptor.app: http://docs.velociraptor.app/announcements/advisories/cve-2026-64954/ github.com: https://github.com/Velocidex/velociraptor/commit/d7de958e846d3742a7a3a8538fd463e4f12fc528

Credits

Reported independently by Tristan Madani (Talence Security) Reported independently by Yuval Miller Reported independently by Leon Kayaliev