CVE-2026-18348
Received Received - Intake

Missing Authorization Check in Velociraptor VQL Plugins

Vulnerability report for CVE-2026-18348, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: Rapid7, Inc.

Description

Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst-role user can initiate attacker-controlled outbound network connections from the Velociraptor server, bypassing the NETWORK ACL permission boundary. This enables internal network reconnaissance via port oracle and potential data exfiltration to external endpoints.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
velocidex velociraptor to 0.77.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a missing authorization check in Velociraptor's upload_azure, upload_sftp, and upload_smb VQL plugins. An authenticated user with the analyst role can bypass the NETWORK ACL permission boundary to initiate unauthorized outbound network connections from the Velociraptor server.

Detection Guidance

Check Velociraptor server logs for unauthorized outbound connections initiated by analyst-role users. Review VQL plugin usage for upload_azure, upload_sftp, and upload_smb functions. Monitor network traffic for unexpected connections from the Velociraptor server to external endpoints.

Impact Analysis

An attacker with analyst access could perform internal network reconnaissance like port scanning or exfiltrate data to external endpoints by exploiting this flaw to create unauthorized network connections.

Compliance Impact

This vulnerability allows unauthorized outbound network connections and potential data exfiltration, which could violate data protection requirements under GDPR (e.g., unauthorized data transfers) and HIPAA (e.g., unauthorized access to protected health information). The lack of authorization checks undermines access control policies required by these standards.

Mitigation Strategies

Upgrade Velociraptor to version 0.77.2 or later to apply the authorization checks. Ensure all users with analyst role have the NETWORK permission explicitly granted. Review and restrict NETWORK ACL permissions to prevent unauthorized outbound connections.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18348. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart