CVE-2026-64954
Velociraptor collect_client() Permissions Bypass
CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th
Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the authorization provider. This allows a user who can run arbitrary VQL (usually with the "analyst" role) to launch new collections (usually requires the "investigator" role). This vulnerability is an escalation from an analyst to investigator role.
| CWE | CWE-862 |
| Vendor | rapid7 |
| Product | velociraptor |
| Published | Aug 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for rapid7 velociraptor
Be the first to know when new high vulnerabilities affecting rapid7 velociraptor are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None
Affected Versions
Rapid7 / Velociraptor
0 < 0.77.2
References
Credits
Reported independently by Tristan Madani (Talence Security) Reported independently by Yuval Miller Reported independently by Leon Kayaliev