Description
Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. However, no such check was implemented for client monitoring artifacts. Additionally there was no requirement that client monitoring artifacts carry the CLIENT_EVENTS type. This allows any user who can schedule client monitoring artifacts to also schedule otherwise restricted artifacts (such as Linux.Sys.BashShell).
Published: 2026-09-10
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

Velociraptor’s client monitoring artifacts should be gated by permissions, but the software omitted a check for EXECVE permission and the requirement that artifacts carry the CLIENT_EVENTS type. As a result, an attacker who can schedule any client monitoring artifact can also schedule privileged artifacts such as Linux.Sys.BashShell, which allows arbitrary command execution on endpoints. The weakness is a form of incorrect authorization, identified as CWE-732.

Affected Systems

All versions of Rapid7 Velociraptor that have not yet incorporated the recent fix are potentially affected. The advisory does not list specific version ranges, so any installed instance that did not apply the latest fix is vulnerable.

Risk and Exploitability

The CVSS score of 9.9 indicates critical severity. EPSS is not reported, and the vulnerability is not yet listed in CISA’s KEV catalog. An attacker with the ability to schedule client monitoring artifacts—typically any authenticated user with artifact scheduling rights—can bypass permission checks and gain arbitrary command execution on endpoints. The lack of a CLIENT_EVENTS type requirement further simplifies the exploitation path, making the vulnerability highly exploitable in environments where artifact scheduling permissions are broadly granted.

Generated by OpenCVE AI on September 10, 2026 at 04:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Velociraptor to the latest release that includes permission checks for client monitoring artifacts.
  • Restrict scheduling rights for client monitoring artifacts to a minimal set of trusted users or groups.
  • Verify that all client monitoring artifacts are assigned the CLIENT_EVENTS type and remove or reclassify those that are not.

Generated by OpenCVE AI on September 10, 2026 at 04:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Rapid7
Rapid7 velociraptor
Vendors & Products Rapid7
Rapid7 velociraptor

Thu, 10 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
Description Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. However, no such check was implemented for client monitoring artifacts. Additionally there was no requirement that client monitoring artifacts carry the CLIENT_EVENTS type. This allows any user who can schedule client monitoring artifacts to also schedule otherwise restricted artifacts (such as Linux.Sys.BashShell).
Title Velociraptor Required Permissions bypass by using client monitoring queries
Weaknesses CWE-732
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L'}


Subscriptions

Rapid7 Velociraptor
cve-icon MITRE

Status: PUBLISHED

Assigner: rapid7

Published:

Updated: 2026-09-11T03:56:12.052Z

Reserved: 2026-08-11T23:11:22.885Z

Link: CVE-2026-19583

cve-icon Vulnrichment

Updated: 2026-09-10T17:36:45.479Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-10T03:16:59.010

Modified: 2026-09-11T04:17:24.930

Link: CVE-2026-19583

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T08:45:09Z

Weaknesses
  • CWE-732

    Incorrect Permission Assignment for Critical Resource