CVE-2026-77798
Received Received - Intake

Deadlock in Velociraptor User Management Module

Vulnerability report for CVE-2026-77798, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: Rapid7, Inc.

Description

Velociraptor contains a deadlock condition that may be triggered by authenticated users. The issue stems from a lock management bug in the user management module.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-24
AI Q&A
2026-09-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
velocidex velociraptor *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-833 The product contains multiple threads or executable segments that are waiting for each other to release a necessary lock, resulting in deadlock.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a deadlock condition in Velociraptor caused by a lock management bug in the user management module. It can be triggered by authenticated users, potentially leading to system hangs or unresponsiveness.

Detection Guidance

The vulnerability involves a deadlock in Velociraptor's user management module. Monitor for system hangs or unresponsive processes during user management operations. Check logs for repeated failed authentication attempts or user-related operations that trigger timeouts. Use system monitoring tools like top, htop, or ps to observe CPU and memory usage spikes during user management tasks.

Impact Analysis

The deadlock may cause service disruptions by freezing operations dependent on user management. Since it requires authentication, only authorized users could exploit this to degrade system performance or cause denial-of-service conditions.

Compliance Impact

The vulnerability is a deadlock condition triggered by authenticated users due to a lock management bug in the user management module. This could lead to denial-of-service conditions, potentially disrupting access controls and audit logging required by GDPR and HIPAA.

Mitigation Strategies

Apply the patch from the commit that fixes the deadlock in the user manager module. Restrict OrgId modifications to HTTP headers only and ensure Docker containers do not override existing config files.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77798. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart