Description
Velociraptor allows collection of VQL queries packaged into Artifacts from endpoints. These artifacts can be used to do anything and usually run with elevated permissions. To limit access to some dangerous artifact, Velociraptor allows for those to require high permissions like EXECVE to launch.

The `Windows.Sysinternals.SysmonLogForward` is a monitoring artifact used to forward sysmon events to the server. The artifact allows the user to specify an arbitrary binary path as a parameter, and did not enforce an additional required permission, allowing users with COLLECT_CLIENT permissions (normally given by the "Investigator" role) to collect it from endpoints and run a different binary program than the installed sysmon binary.
To successfully exploit this vulnerability the user must already have access to collect artifacts from the endpoint (i.e. have the COLLECT_CLIENT given typically by the "Investigator" role).
Published: 2026-10-05
Score: 5.5 Medium
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

Velociraptor includes an artifact called Windows.Sysinternals.SysmonLogForward that is intended to forward Sysmon events to the server. The artifact accepts an arbitrary binary path as a parameter but does not enforce an additional required permission. Users who have typically assigned to the Investigator role, can collect this artifact from endpoints and, because of the missing permission check, can specify a malicious binary to be executed with elevated privileges. The vulnerability therefore allows the exploitation of privilege escalation by instructing endpoints to run an attacker‑controlled program with the privileges of the running artifact.

Affected Systems

The vulnerability affects Rapid7 Velociraptor deployments on Linux platforms. No specific product version information is listed, so all current versions that include the Windows.Sysinternals.SysmonLogForward artifact are potentially impacted.

Risk and Exploitability

The CVSS base score of 5.5 indicates moderate severity, and the EPSS score is not available. The vulnerability is not listed in CISA KEV. An attacker who already has the Investigator role can enable the exploit by collecting the artifact, specifying an arbitrary binary path, and causing the endpoint to execute that binary with the artifact’s elevated privileges. Because the flaw relies on a privilege that many analysts normally possess, the attack vector is likely internal or requires a legitimate user account with this role.

Generated by OpenCVE AI on October 5, 2026 at 20:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest Velociraptor release that removes the arbitrary binary path parameter or enforces the required EXECVE permission for this artifact.
  • Revise the artifact’s definition to require EXECVE or higher permissions and lock down the COLLECT_CLIENT privilege to only trusted users.
  • Audit existing artifact configurations to ensure no other artifacts allow arbitrary binary execution, and disable or delete SysmonLogForward if it is not required for operations.

Generated by OpenCVE AI on October 5, 2026 at 20:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Description Velociraptor allows collection of VQL queries packaged into Artifacts from endpoints. These artifacts can be used to do anything and usually run with elevated permissions. To limit access to some dangerous artifact, Velociraptor allows for those to require high permissions like EXECVE to launch. The `Windows.Sysinternals.SysmonLogForward` is a monitoring artifact used to forward sysmon events to the server. The artifact allows the user to specify an arbitrary binary path as a parameter, and did not enforce an additional required permission, allowing users with COLLECT_CLIENT permissions (normally given by the "Investigator" role) to collect it from endpoints and run a different binary program than the installed sysmon binary. To successfully exploit this vulnerability the user must already have access to collect artifacts from the endpoint (i.e. have the COLLECT_CLIENT given typically by the "Investigator" role).
Title Velociraptor privilege escalation via SysmonLogForward client monitoring artifact
First Time appeared Rapid7
Rapid7 velociraptor
Weaknesses CWE-276
CPEs cpe:2.3:a:rapid7:velociraptor:*:*:linux:*:*:*:*:*
Vendors & Products Rapid7
Rapid7 velociraptor
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L'}


Subscriptions

Rapid7 Velociraptor
cve-icon MITRE

Status: PUBLISHED

Assigner: rapid7

Published:

Updated: 2026-10-05T19:07:47.590Z

Reserved: 2026-08-24T14:44:51.844Z

Link: CVE-2026-78413

cve-icon Vulnrichment

Updated: 2026-10-05T19:07:43.717Z

cve-icon NVD

Status : Received

Published: 2026-10-05T18:17:37.383

Modified: 2026-10-05T20:17:27.143

Link: CVE-2026-78413

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T20:30:22Z

Weaknesses
  • CWE-276

    Incorrect Default Permissions