CVE-2026-18652
Received Received - Intake

Path Traversal in Velociraptor GUI

Vulnerability report for CVE-2026-18652, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-12

Assigner: Rapid7, Inc.

Description

Velociraptor allows reading Stacked result sets from the GUI.Β  Velociraptor's multi-tenant design stores sub orgs within the datastore directory.Β The path requested by the GUI is not correctly checked against the prefix deny list, allowing result sets to read from denied prefixes. In particular, a user with read access to the root org can access result sets from child orgs.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-12
Generated
2026-08-12
AI Q&A
2026-08-12
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
velociraptor velociraptor to 0.77.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-18652 is a vulnerability in Velociraptor, an incident response and digital forensics tool. It allows users with read access to the root organization to bypass path restrictions and access result sets from child organizations. This happens because the GUI does not properly validate paths against a deny list, enabling unauthorized access to stacked result sets stored in the datastore directory.

Detection Guidance

Check Velociraptor version with 'velociraptor version' and compare against 0.77.2. Review GUI access logs for unauthorized data access attempts from root org users to child org result sets.

Impact Analysis

A user with the 'reader' role in the root organization can exploit this to access unauthorized data from child organizations. The impact is limited to unauthorized data access without affecting system integrity or availability. No user interaction is required for exploitation.

Mitigation Strategies

Restrict root org access to trusted users only. Update Velociraptor to version 0.77.2 or later to patch the flaw. Monitor for unusual data access patterns between organizations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18652. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart