CVE-2026-18652
Velociraptor vulnerability analysis and mitigation

Overview

CVE-2026-18652 is a Missing Authorization vulnerability in Rapid7's Velociraptor DFIR platform that allows an authenticated user with read access to the root organization to access result sets belonging to child organizations in a multi-tenant deployment. The flaw was published on August 12, 2026, and affects all Velociraptor versions prior to 0.77.2. It carries a CVSS v3.1 base score of 4.9 (Medium), reflecting the requirement for high privileges and the confidentiality-only impact (GitHub Advisory, Velociraptor Advisory).

Technical details

The root cause is classified as CWE-862 (Missing Authorization). Velociraptor's multi-tenant architecture stores sub-organization data within subdirectories of the main datastore directory; when the GUI retrieves "stacked" result sets, the requested path is not correctly validated against the configured prefix deny list. This allows an attacker to craft a path that bypasses the deny list and reads result sets from child organization directories they are not authorized to access. Exploitation requires an authenticated session with at least read-level access to the root organization, and no user interaction or special configuration is needed beyond that (GitHub Advisory).

Impact

Successful exploitation results in unauthorized read access to forensic result sets stored in child organizations within a multi-tenant Velociraptor deployment, constituting a high confidentiality impact. There is no integrity or availability impact. In environments where multiple tenants (e.g., separate clients or business units) share a Velociraptor instance, this could expose sensitive investigation data, endpoint telemetry, or hunt results belonging to other organizations to an unauthorized root-org user (GitHub Advisory, Velociraptor Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is approximately 0.377%, placing it in the 31st percentile for exploitation likelihood within 30 days. Exploitation is not automatable, as it requires a valid authenticated session with high privileges in the root organization (GitHub Advisory).

Exploitation steps

  1. Authentication: Log in to the Velociraptor GUI with an account that has read access to the root organization in a multi-tenant deployment.
  2. Identify target child org: Enumerate or infer the datastore directory structure to identify the path prefix associated with a child organization's result sets.
  3. Craft malicious path request: Construct a GUI request for stacked result sets using a path that references a child organization's datastore prefix — one that should be blocked by the deny list but is not correctly validated.
  4. Retrieve unauthorized data: Submit the crafted request; the server returns result sets from the child organization's datastore directory, exposing forensic investigation data, hunt results, or endpoint telemetry belonging to that tenant (GitHub Advisory, Velociraptor Advisory).

Indicators of compromise

  • Logs: Velociraptor server audit logs showing authenticated root-org user accounts making GUI requests to result set paths containing child organization directory prefixes (e.g., paths referencing /orgs/<child_org_id>/ from a root-org session).
  • Network: Unusual or repeated HTTP requests from a root-org user session to API endpoints that retrieve stacked result sets, particularly targeting paths outside the root org's expected namespace.
  • Behavioral: A root-org user account accessing result sets at a higher-than-expected volume or accessing result sets from hunts/collections they did not initiate.

Mitigation and workarounds

Rapid7 has released Velociraptor version 0.77.2, which correctly validates requested paths against the prefix deny list; upgrading to this version is the recommended remediation (Velociraptor Advisory, GitHub Advisory). As a temporary workaround prior to patching, administrators should restrict read access to the root organization to only fully trusted users who explicitly require it, minimizing the pool of accounts that could exploit this flaw. Reviewing Velociraptor access logs to identify any anomalous cross-org result set access is also recommended.

Additional resources


SourceThis report was generated using AI

Related Velociraptor vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64952MEDIUM6.5
  • Velociraptor logoVelociraptor
  • cpe:2.3:a:rapid7:velociraptor
NoYesAug 12, 2026
CVE-2026-64955MEDIUM6.1
  • Velociraptor logoVelociraptor
  • cpe:2.3:a:rapid7:velociraptor
NoYesAug 12, 2026
CVE-2026-18652MEDIUM4.9
  • Velociraptor logoVelociraptor
  • cpe:2.3:a:rapid7:velociraptor
NoYesAug 12, 2026
CVE-2026-64951LOW3.5
  • Velociraptor logoVelociraptor
  • cpe:2.3:a:rapid7:velociraptor
NoYesAug 12, 2026
CVE-2026-15371NONEN/A
  • Velociraptor logoVelociraptor
  • cpe:2.3:a:rapid7:velociraptor
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management