CVE-2026-6290
Velociraptor vulnerability analysis and mitigation

Overview

CVE-2026-6290 is an Incorrect Authorization vulnerability in Rapid7's Velociraptor DFIR platform affecting the query() plugin. It allows an authenticated GUI user with access to one organization to execute VQL queries against other organizations they are not authorized to access, using their current ACL token. All Velociraptor versions prior to 0.76.3 (i.e., ≤ 0.76.2) are affected. The vulnerability was published on April 15, 2026, and carries a CVSS v3.1 base score of 9.1 (Critical) (GitHub Advisory, Velociraptor Advisory).

Technical details

The root cause is CWE-863 (Incorrect Authorization): the query() plugin in Velociraptor's notebook functionality fails to enforce organization-level access controls when executing VQL queries, instead relying solely on the user's current ACL token without validating whether that token grants access to the target organization (GitHub Advisory). An authenticated attacker with GUI access to any organization can craft a notebook cell invoking the query() plugin with a target org parameter, effectively bypassing the intended multi-tenancy isolation. The permissions applied in the unauthorized target organization mirror those the attacker holds in their own organization, meaning a high-privileged user in one org gains equivalent high-privileged access across all orgs (Velociraptor Advisory). No public proof-of-concept exploit code has been identified.

Impact

Successful exploitation enables an authenticated attacker to perform unauthorized cross-organization access within a Velociraptor multi-tenant deployment, with confidentiality, integrity, and availability all rated High. An attacker can exfiltrate sensitive forensic data and endpoint telemetry from organizations they should not have access to, modify resources or configurations across organizational boundaries, and potentially disrupt operations in affected orgs. The changed scope means a compromise in one organization can cascade to all other organizations within the same Velociraptor instance (GitHub Advisory, Velociraptor Advisory).

Exploitation steps

  1. Gain Authenticated Access: Obtain valid credentials for a Velociraptor GUI account with access to at least one organization (e.g., through phishing, credential theft, or insider access).
  2. Navigate to Notebook: Log into the Velociraptor GUI and open or create a notebook within the organization the attacker has legitimate access to.
  3. Invoke the query() Plugin: In a notebook cell, craft a VQL query using the query() plugin and specify a target organization the attacker is not authorized to access (e.g., by passing the target org identifier as a parameter).
  4. Execute Cross-Org VQL: Submit the notebook cell. Due to the authorization bypass, the server processes the query against the target organization using the attacker's current ACL token, granting the same permissions the attacker holds in their own org.
  5. Exfiltrate or Modify Data: Use the unauthorized VQL access to enumerate endpoints, retrieve forensic artifacts, exfiltrate sensitive data, or modify configurations within the target organization (GitHub Advisory, Velociraptor Advisory).

Indicators of compromise

  • Logs: Velociraptor audit logs showing VQL query() plugin invocations from a user in one organization targeting a different organization's resources; unexpected cross-org query activity in server audit trails.
  • Logs: Notebook cell execution events attributed to users who do not have explicit membership or permissions in the queried organization.
  • Network: Unusual data volumes or query results returned to a single authenticated session spanning multiple organizational contexts.
  • Behavioral: A single user account generating VQL queries that reference org identifiers outside their assigned organization, particularly from notebook cells.

Mitigation and workarounds

Rapid7 has released Velociraptor version 0.76.3, which patches this vulnerability; all users should upgrade immediately (Velociraptor Advisory, GitHub Advisory). As an interim workaround where patching is not immediately possible, administrators should restrict notebook functionality for users who do not require it, enforce strong access controls on GUI accounts, and monitor audit logs for suspicious cross-organization VQL query activity. Review all authenticated user accounts for least-privilege compliance and consider disabling multi-org access for accounts that do not require it.

Community reactions

The vulnerability was assigned and disclosed by Rapid7 on April 15, 2026, with an official advisory published on the Velociraptor documentation site (Velociraptor Advisory). The GitHub Advisory Database rated it Critical (9.1 CVSS), and it was reviewed and confirmed by GitHub's security team on April 16, 2026 (GitHub Advisory). Community discussion was observed on Bluesky and aggregated by threat intelligence platforms shortly after disclosure, though no significant researcher commentary or media coverage beyond standard vulnerability tracking has been identified.

Additional resources


SourceThis report was generated using AI

Related Velociraptor vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-6290CRITICAL9.1
  • Velociraptor logoVelociraptor
  • www.velocidex.com/golang/velociraptor
NoYesApr 15, 2026
CVE-2026-8795HIGH7.8
  • Velociraptor logoVelociraptor
  • cpe:2.3:a:rapid7:velociraptor
NoYesJun 09, 2026
CVE-2026-7573HIGH7.7
  • Velociraptor logoVelociraptor
  • cpe:2.3:a:rapid7:velociraptor
NoYesMay 06, 2026
CVE-2026-7572MEDIUM5.5
  • Velociraptor logoVelociraptor
  • www.velocidex.com/golang/velociraptor
NoYesMay 06, 2026
CVE-2026-6948MEDIUM4.9
  • Velociraptor logoVelociraptor
  • cpe:2.3:a:rapid7:velociraptor
NoYesMay 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management