Impact
Velociraptor’s client monitoring artifacts should be gated by permissions, but the software omitted a check for EXECVE permission and the requirement that artifacts carry the CLIENT_EVENTS type. As a result, an attacker who can schedule any client monitoring artifact can also schedule privileged artifacts such as Linux.Sys.BashShell, which allows arbitrary command execution on endpoints. The weakness is a form of incorrect authorization, identified as CWE-732.
Affected Systems
All versions of Rapid7 Velociraptor that have not yet incorporated the recent fix are potentially affected. The advisory does not list specific version ranges, so any installed instance that did not apply the latest fix is vulnerable.
Risk and Exploitability
The CVSS score of 9.9 indicates critical severity. EPSS is not reported, and the vulnerability is not yet listed in CISA’s KEV catalog. An attacker with the ability to schedule client monitoring artifacts—typically any authenticated user with artifact scheduling rights—can bypass permission checks and gain arbitrary command execution on endpoints. The lack of a CLIENT_EVENTS type requirement further simplifies the exploitation path, making the vulnerability highly exploitable in environments where artifact scheduling permissions are broadly granted.
OpenCVE Enrichment