CVE-2026-78413
Received Received - Intake

Privilege Escalation in Velociraptor via SysmonLogForward Artifact

Vulnerability report for CVE-2026-78413, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Rapid7, Inc.

Description

Velociraptor allows collection of VQL queries packaged into Artifacts from endpoints. These artifacts can be used to do anything and usually run with elevated permissions. To limit access to some dangerous artifact, Velociraptor allows for those to require high permissions like EXECVE to launch. TheΒ `Windows.Sysinternals.SysmonLogForward` is a monitoring artifact used to forward sysmon events to the server. The artifact allows the user to specify an arbitrary binary path as a parameter, andΒ did not enforce an additional required permission, allowing users with COLLECT_CLIENT permissions (normally given by the "Investigator" role) to collect it from endpoints and run a different binary program than the installed sysmon binary. To successfully exploit this vulnerability the user must already have access to collect artifacts from the endpoint (i.e. have the COLLECT_CLIENT given typically by the "Investigator" role).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Rapid7 Velociraptor 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-276 During installation, installed file permissions are set to allow anyone to modify those files.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Velociraptor allows users with COLLECT_CLIENT permissions to run an arbitrary binary through the Windows.Sysinternals.SysmonLogForward artifact. The artifact normally forwards Sysmon events but permits specifying a custom binary path without enforcing elevated permissions like EXECVE. This could let attackers execute malicious programs instead of the intended Sysmon binary.

Detection Guidance

Check Velociraptor version with 'velociraptor version' to confirm it is below 0.77.3. Inspect artifact definitions for Windows.Sysinternals.SysmonLogForward to verify if required_permissions are missing. Look for unexpected binary executions in Sysmon logs or Velociraptor client event logs.

Impact Analysis

If exploited, this flaw could allow unauthorized execution of arbitrary code on endpoints with elevated privileges. Attackers with Investigator role access could run malicious binaries, potentially leading to data theft, system compromise, or further network infiltration.

Compliance Impact

This vulnerability could lead to unauthorized access or data exfiltration, violating GDPR's data protection principles and HIPAA's security requirements. Organizations using Velociraptor must ensure proper access controls and update to mitigate compliance risks.

Mitigation Strategies

Upgrade Velociraptor to version 0.77.3 or later. Review and update artifact permissions to enforce required_permissions like EXECVE. Restrict COLLECT_CLIENT permissions to only trusted users. Monitor for unauthorized artifact collections or binary executions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78413. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart