Impact
Velociraptor allows users to schedule new collections through VQL in notebooks. The system requires the COLLECT_CLIENT permission, but this check is bypassed when a user runs a VQL query that resets the authorization provider. Consequently, an analyst who can execute arbitrary VQL can start collections that normally require the investigator role, effectively gaining elevated privileges. The weakness is classified as unverified access control, CWE-862.
Affected Systems
The affected product is Rapid7 Velociraptor. All current releases are vulnerable until the vendor releases a fix; no specific versions are presently listed in the advisory.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity vulnerability. EPSS data is not available, and the vulnerability is not currently listed in CISA KEV. The likely attack vector involves an analyst with VQL execution rights resetting the authorization provider and launching new collections. This bypass does not require additional network access or external exploitation agents, so the risk to systems where such roles exist is considerable.
OpenCVE Enrichment