Impact
Missing authorization checks in the upload_azure, upload_sftp, and upload_smb VQL plugins let an authenticated analyst‑role user trigger outbound connections from the Velociraptor server, bypassing the NETWORK ACL boundary. This flaw can be leveraged for internal network reconnaissance, such as port oracle scans, and may allow data exfiltration to external destinations. The weakness is a missing permission check (CWE‑863) and is reflected in a CVSS score of 4.1, indicating moderate severity.
Affected Systems
Rapid7 Velociraptor; the issue affects the upload_azure, upload_sftp and upload_smb plugins, with no specific product version listed. Users operating these plugins under an analyst role are at risk.
Risk and Exploitability
The vulnerability is exploitable only by users with an authenticated analyst role, so it requires legitimate credentials. The CVSS score of 4.1 places it in the moderate severity range, and the EPSS score is not available, but the fact that it is not in KEV suggests limited published exploits. The risk is primarily the ability to bypass the intended network access controls and conduct reconnaissance or exfiltrate data from the internal network.
OpenCVE Enrichment