This allows a user who can run arbitrary VQL (usually with the "analyst" role) to launch new collections (usually requires the "investigator" role). This vulnerability is an escalation from an analyst to investigator role.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 12 Aug 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rapid7
Rapid7 velociraptor |
|
| Vendors & Products |
Rapid7
Rapid7 velociraptor |
Wed, 12 Aug 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the authorization provider. This allows a user who can run arbitrary VQL (usually with the "analyst" role) to launch new collections (usually requires the "investigator" role). This vulnerability is an escalation from an analyst to investigator role. | |
| Title | Velociraptor collect_client() Permissions Bypass | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2026-08-12T04:26:32.169Z
Reserved: 2026-07-21T08:32:47.510Z
Link: CVE-2026-64954
No data.
Status : Received
Published: 2026-08-12T05:19:17.893
Modified: 2026-08-12T05:19:17.893
Link: CVE-2026-64954
No data.
OpenCVE Enrichment
Updated: 2026-08-12T17:00:06Z
-
CWE-862
Missing Authorization