Impact
Velociraptor compiles VQL queries for hunts and stores the compiled code internally to avoid recompilation on each endpoint. The field "compiled_collector_args" is marked internal but can be set via the user API. As a result, a user with the minimal "investigator" role can schedule a hunt and inject arbitrary compiled VQL statements. This action bypasses the normal ACL checks that would restrict query execution, enabling the investigator to run any VQL statement as if they had administrator privileges on the Velociraptor server, potentially exposing or manipulating data across all monitored endpoints.
Affected Systems
The Rapid7 Velociraptor platform is affected. Specific product and version information are not provided, so any deployment of Velociraptor should be treated as at risk until a vendor fix is released.
Risk and Exploitability
The CVSS score of 9.9 indicates a critical severity. EPSS data is unavailable, but the vulnerability requires only an investigator‑level account to leverage, which many organizations grant. KEV listing is absent, yet the combination of a high severity score and easy-to‑obtain privilege makes the risk high. Exploitation requires user API access, so the likely attack vector is via an authorized API call that substitutes the compiled VQL payload.
OpenCVE Enrichment