CVE-2026-19072: CWE-1269 Product released in Non-Release configuration in Rapid7 Velociraptor
Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each endpoint in the hunt. Although the field "compiled_collector_args" is an internal field, Velociraptor allowed the field to be set from a user API call. This allows another user who can schedule a hunt (minimal role of "investigator" ) to set the compiled VQL statements for the hunt bypassing any ACL checks that would normally be applied. This flaw can then be escalated to allow the "investigator" user to run arbitrary VQL statements as an administrator user on the Velociraptor server.
AI Analysis
Technical Summary
Velociraptor internally stores compiled VQL in the hunt object to optimize artifact execution. The internal field 'compiled_collector_args' was improperly exposed to user API calls, allowing users with minimal privileges ('investigator' role) to set compiled VQL statements directly. This bypasses normal ACL checks and escalates privileges, permitting execution of arbitrary VQL commands as an administrator on the server. The vulnerability affects Velociraptor versions >=0 and <0.77.2 and has a CVSS 3.1 score of 9.9, indicating critical severity.
Potential Impact
An attacker with the 'investigator' role can escalate privileges to administrator by injecting arbitrary VQL statements, potentially compromising confidentiality, integrity, and availability of the Velociraptor server and its managed endpoints.
Mitigation Recommendations
A fix is available in Velociraptor version 0.77.2. Users should upgrade to version 0.77.2 or later to remediate this vulnerability. No additional mitigation steps are indicated.
CVE-2026-19072: CWE-1269 Product released in Non-Release configuration in Rapid7 Velociraptor
Description
Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each endpoint in the hunt. Although the field "compiled_collector_args" is an internal field, Velociraptor allowed the field to be set from a user API call. This allows another user who can schedule a hunt (minimal role of "investigator" ) to set the compiled VQL statements for the hunt bypassing any ACL checks that would normally be applied. This flaw can then be escalated to allow the "investigator" user to run arbitrary VQL statements as an administrator user on the Velociraptor server.
CVSS v3.1
Score 9.9critical
Affected software
Rapid7
Velociraptor
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Velociraptor internally stores compiled VQL in the hunt object to optimize artifact execution. The internal field 'compiled_collector_args' was improperly exposed to user API calls, allowing users with minimal privileges ('investigator' role) to set compiled VQL statements directly. This bypasses normal ACL checks and escalates privileges, permitting execution of arbitrary VQL commands as an administrator on the server. The vulnerability affects Velociraptor versions >=0 and <0.77.2 and has a CVSS 3.1 score of 9.9, indicating critical severity.
Potential Impact
An attacker with the 'investigator' role can escalate privileges to administrator by injecting arbitrary VQL statements, potentially compromising confidentiality, integrity, and availability of the Velociraptor server and its managed endpoints.
Mitigation Recommendations
A fix is available in Velociraptor version 0.77.2. Users should upgrade to version 0.77.2 or later to remediate this vulnerability. No additional mitigation steps are indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- rapid7
- Date Reserved
- 2026-08-06T09:16:50.394Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab51fa1f7a7c5410656cdf8
Added to database: 09/24/2026, 13:03:29 UTC
Last enriched: 09/24/2026, 13:17:45 UTC
Last updated: 09/25/2026, 04:33:14 UTC
Views: 46
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.