CVE-2026-19583
Awaiting Analysis Awaiting Analysis - Queue

Client Monitoring Artifact Permission Bypass in Velociraptor

Vulnerability report for CVE-2026-19583, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-11

Assigner: Rapid7, Inc.

Description

Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. However, no such check was implemented for client monitoring artifacts. Additionally there was no requirement that client monitoring artifacts carry the CLIENT_EVENTS type. This allows any user who can schedule client monitoring artifacts to also schedule otherwise restricted artifacts (such as Linux.Sys.BashShell).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-11
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
velociraptor velociraptor to 0.77.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-732 The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Velociraptor allows users to bypass permission checks for sensitive artifacts by using client monitoring queries. Normally, restricted artifacts like Linux.Sys.BashShell require specific permissions such as EXECVE to execute. However, client monitoring artifacts lacked these permission checks and did not require the CLIENT_EVENTS type, enabling unauthorized users to schedule and execute otherwise restricted artifacts.

Detection Guidance

To detect this vulnerability, check if any user with the investigator role can schedule client monitoring artifacts without proper permission enforcement. Review Velociraptor logs for unauthorized artifact scheduling, particularly for restricted artifacts like Linux.Sys.BashShell. Ensure client monitoring artifacts have the CLIENT_EVENTS type and verify permission checks are enforced.

Impact Analysis

An attacker with access to schedule client monitoring artifacts could exploit this flaw to execute restricted commands on endpoints, potentially gaining unauthorized control over systems. This could lead to data breaches, system compromise, or further lateral movement within a network, depending on the privileges of the compromised account.

Compliance Impact

This vulnerability could violate compliance requirements by enabling unauthorized access to sensitive data or systems. For GDPR, it may lead to unauthorized data processing or breaches. For HIPAA, it could allow access to protected health information without proper authorization, resulting in non-compliance with security and privacy controls.

Mitigation Strategies

Upgrade Velociraptor to version 0.77.2 or later to apply the patch. Review and restrict user roles to ensure only authorized users can schedule client monitoring artifacts. Audit existing artifacts and permissions to confirm no unauthorized scheduling has occurred.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19583. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart