CVE-2026-64954: CWE-862: Missing Authorization in Rapid7 Velociraptor
Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the authorization provider. This allows a user who can run arbitrary VQL (usually with the "analyst" role) to launch new collections (usually requires the "investigator" role). This vulnerability is an escalation from an analyst to investigator role.
AI Analysis
Technical Summary
Velociraptor permits scheduling new collections via VQL queries in notebooks, requiring the COLLECT_CLIENT permission. However, this permission check is bypassed if a user can execute a VQL query that resets the authorization provider. As a result, a user with the analyst role (who can run arbitrary VQL) can escalate privileges to investigator role capabilities by launching new collections. This is a missing authorization vulnerability categorized under CWE-862. The issue affects versions before 0.77.2 and has a CVSS 3.1 score of 8.2, indicating high severity. No vendor advisory or patch information is currently available.
Potential Impact
An attacker with analyst-level access can escalate privileges to investigator-level by bypassing authorization controls, enabling them to schedule new collections that they normally would not have permission to perform. This could lead to unauthorized data collection and potential exposure of sensitive information. The vulnerability does not affect availability but impacts confidentiality and integrity significantly.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict the ability to run arbitrary VQL queries to trusted users only, and monitor for unusual activity related to authorization provider resets or collection scheduling.
CVE-2026-64954: CWE-862: Missing Authorization in Rapid7 Velociraptor
Description
Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the authorization provider. This allows a user who can run arbitrary VQL (usually with the "analyst" role) to launch new collections (usually requires the "investigator" role). This vulnerability is an escalation from an analyst to investigator role.
CVSS v3.1
Score 8.2high
Affected software
Rapid7
Velociraptor
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Velociraptor permits scheduling new collections via VQL queries in notebooks, requiring the COLLECT_CLIENT permission. However, this permission check is bypassed if a user can execute a VQL query that resets the authorization provider. As a result, a user with the analyst role (who can run arbitrary VQL) can escalate privileges to investigator role capabilities by launching new collections. This is a missing authorization vulnerability categorized under CWE-862. The issue affects versions before 0.77.2 and has a CVSS 3.1 score of 8.2, indicating high severity. No vendor advisory or patch information is currently available.
Potential Impact
An attacker with analyst-level access can escalate privileges to investigator-level by bypassing authorization controls, enabling them to schedule new collections that they normally would not have permission to perform. This could lead to unauthorized data collection and potential exposure of sensitive information. The vulnerability does not affect availability but impacts confidentiality and integrity significantly.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict the ability to run arbitrary VQL queries to trusted users only, and monitor for unusual activity related to authorization provider resets or collection scheduling.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- rapid7
- Date Reserved
- 2026-07-21T08:32:47.510Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a7c6c5abf8831d5398f6fba
Added to database: 08/12/2026, 12:51:38 UTC
Last enriched: 08/12/2026, 12:53:15 UTC
Last updated: 09/26/2026, 13:47:47 UTC
Views: 71
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.