
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-18640 is a path traversal vulnerability in Rapid7's Velociraptor DFIR platform affecting the NewNotebook API. An authenticated user with NOTEBOOK_EDIT permission can write notebook records outside the organization's designated data store directory, potentially overwriting critical metadata files such as ACL records and hunt configurations. All versions prior to 0.77.2 are affected. The vulnerability carries a CVSS v3.1 base score of 7.1 (High) and was publicly disclosed on August 11, 2026 (Velociraptor Advisory).
The root cause is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal). The NewNotebook API fails to adequately sanitize user-supplied parameters, allowing an attacker to craft a request that causes the server to write a file outside the intended org-scoped data store directory. The written file is constrained to the .json.db extension, but this is sufficient to overwrite other metadata files stored in that format, including ACL records and hunt definitions. Exploitation requires network access to the Velociraptor server and a valid account with NOTEBOOK_EDIT permission — no elevated privileges beyond this are needed (Velociraptor Advisory).
Successful exploitation allows an authenticated attacker to overwrite arbitrary .json.db metadata files outside the org's data store, including ACL records, hunt configurations, and other operational data. This can result in significant data corruption, disruption of active forensic hunts, and potential privilege escalation if ACL files are manipulated to grant unauthorized permissions. Availability is also partially impacted as corrupted metadata may render Velociraptor features inoperable. Confidentiality is not directly impacted by this vulnerability (Velociraptor Advisory).
As of the disclosure date, there is no evidence of in-the-wild exploitation, and no public proof-of-concept exploit code has been identified. The NVD SSVC assessment confirms exploitation status as "none" and notes the vulnerability is not automatable, requiring authenticated access with specific permissions. The EPSS score is approximately 0.31%, indicating a low probability of near-term exploitation. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Velociraptor Advisory).
NOTEBOOK_EDIT permission.NewNotebook API endpoint with a manipulated notebook name or path parameter containing path traversal sequences (e.g., ../../) designed to escape the org's data store directory..json.db file outside the org directory, such as an ACL record or hunt configuration file..json.db extension) to the attacker-controlled path, overwriting the target metadata file.NewNotebook API calls with notebook name/path parameters containing ../ or URL-encoded traversal sequences (e.g., %2e%2e%2f)..json.db files appearing outside the expected org data store directory structure; modification timestamps on ACL or hunt .json.db files that do not correspond to legitimate administrative activity.NOTEBOOK_EDIT actions by users who do not typically create notebooks, or notebook creation events at unusual times.Rapid7 has released Velociraptor version 0.77.2, which addresses this vulnerability by properly sanitizing the NewNotebook API parameters to prevent path traversal. All users running versions prior to 0.77.2 should upgrade immediately. No configuration-based workarounds have been published; upgrading to the patched release is the only recommended remediation. As an interim measure, administrators should restrict NOTEBOOK_EDIT permissions to only trusted users until patching is complete (Velociraptor Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."