CVE-2026-18640
Velociraptor vulnerability analysis and mitigation

Overview

CVE-2026-18640 is a path traversal vulnerability in Rapid7's Velociraptor DFIR platform affecting the NewNotebook API. An authenticated user with NOTEBOOK_EDIT permission can write notebook records outside the organization's designated data store directory, potentially overwriting critical metadata files such as ACL records and hunt configurations. All versions prior to 0.77.2 are affected. The vulnerability carries a CVSS v3.1 base score of 7.1 (High) and was publicly disclosed on August 11, 2026 (Velociraptor Advisory).

Technical details

The root cause is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal). The NewNotebook API fails to adequately sanitize user-supplied parameters, allowing an attacker to craft a request that causes the server to write a file outside the intended org-scoped data store directory. The written file is constrained to the .json.db extension, but this is sufficient to overwrite other metadata files stored in that format, including ACL records and hunt definitions. Exploitation requires network access to the Velociraptor server and a valid account with NOTEBOOK_EDIT permission — no elevated privileges beyond this are needed (Velociraptor Advisory).

Impact

Successful exploitation allows an authenticated attacker to overwrite arbitrary .json.db metadata files outside the org's data store, including ACL records, hunt configurations, and other operational data. This can result in significant data corruption, disruption of active forensic hunts, and potential privilege escalation if ACL files are manipulated to grant unauthorized permissions. Availability is also partially impacted as corrupted metadata may render Velociraptor features inoperable. Confidentiality is not directly impacted by this vulnerability (Velociraptor Advisory).

Exploitability

As of the disclosure date, there is no evidence of in-the-wild exploitation, and no public proof-of-concept exploit code has been identified. The NVD SSVC assessment confirms exploitation status as "none" and notes the vulnerability is not automatable, requiring authenticated access with specific permissions. The EPSS score is approximately 0.31%, indicating a low probability of near-term exploitation. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Velociraptor Advisory).

Exploitation steps

  1. Reconnaissance: Identify a Velociraptor server instance and obtain or compromise credentials for an account with NOTEBOOK_EDIT permission.
  2. Craft malicious API request: Construct a request to the NewNotebook API endpoint with a manipulated notebook name or path parameter containing path traversal sequences (e.g., ../../) designed to escape the org's data store directory.
  3. Target metadata file: Specify a target path that resolves to a sensitive .json.db file outside the org directory, such as an ACL record or hunt configuration file.
  4. Submit request: Send the crafted API request to the Velociraptor server. The server writes the notebook record (with .json.db extension) to the attacker-controlled path, overwriting the target metadata file.
  5. Achieve objective: The overwritten ACL or hunt file causes data corruption, disrupts forensic operations, or — if ACL files are manipulated with attacker-controlled content — may alter access control decisions (Velociraptor Advisory).

Indicators of compromise

  • Logs: Velociraptor server logs showing NewNotebook API calls with notebook name/path parameters containing ../ or URL-encoded traversal sequences (e.g., %2e%2e%2f).
  • File System: Unexpected .json.db files appearing outside the expected org data store directory structure; modification timestamps on ACL or hunt .json.db files that do not correspond to legitimate administrative activity.
  • Logs: Audit logs recording NOTEBOOK_EDIT actions by users who do not typically create notebooks, or notebook creation events at unusual times.
  • File System: Corruption or unexpected content changes in ACL records or hunt configuration files within the Velociraptor data store.

Mitigation and workarounds

Rapid7 has released Velociraptor version 0.77.2, which addresses this vulnerability by properly sanitizing the NewNotebook API parameters to prevent path traversal. All users running versions prior to 0.77.2 should upgrade immediately. No configuration-based workarounds have been published; upgrading to the patched release is the only recommended remediation. As an interim measure, administrators should restrict NOTEBOOK_EDIT permissions to only trusted users until patching is complete (Velociraptor Advisory).

Additional resources


SourceThis report was generated using AI

Related Velociraptor vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-15371HIGH8.1
  • Velociraptor logoVelociraptor
  • cpe:2.3:a:rapid7:velociraptor
NoYesAug 18, 2026
CVE-2026-64952MEDIUM6.5
  • Velociraptor logoVelociraptor
  • cpe:2.3:a:rapid7:velociraptor
NoYesAug 12, 2026
CVE-2026-18652MEDIUM6.5
  • Velociraptor logoVelociraptor
  • cpe:2.3:a:rapid7:velociraptor
NoYesAug 12, 2026
CVE-2026-64955MEDIUM6.1
  • Velociraptor logoVelociraptor
  • cpe:2.3:a:rapid7:velociraptor
NoYesAug 12, 2026
CVE-2026-64951LOW3.5
  • Velociraptor logoVelociraptor
  • cpe:2.3:a:rapid7:velociraptor
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management