Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-18640: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Rapid7 VelociraptorCVE-2026-18640
0

CVE-2026-18640 is a path traversal vulnerability in Rapid7 Velociraptor's NewNotebook API. It allows an authenticated user with NOTEBOOK_EDIT permission to write files outside the intended data store directory. The vulnerability permits overwriting metadata files with a .json.db extension, potentially causing data corruption. The issue affects versions prior to 0.77.2. The CVSS score is 7.1, indicating high severity.

Join the discussion
CVE-2026-18639: CWE-290 Authentication bypass by spoofing in Rapid7 VelociraptorCVE-2026-18639
0

CVE-2026-18639 is an authentication bypass vulnerability in Rapid7 Velociraptor when configured with an OIDC identity provider (IdP). The product uses the email claim from the IdP as the username, but some IdPs allow users to change the email claim without verification or do not verify the email at all. This flaw enables an attacker to impersonate another user by setting their email address in the IdP, leading to account takeover.

Join the discussion
CVE-2026-18638: CWE-476 NULL pointer dereference in Rapid7 VelociraptorCVE-2026-18638
0

CVE-2026-18638 is a medium severity vulnerability in Rapid7 Velociraptor versions prior to 0.77.2. It allows any authenticated user, including those with only reader role privileges, to cause a denial of service by terminating the entire server process. This is triggered by sending a SetPassword request with a username that does not exist, resulting in a NULL pointer dereference.

Join the discussion
CVE-2026-18860: CWE-280 Improper handling of insufficient permissions or privileges in Rapid7 VelociraptorCVE-2026-18860
0

CVE-2026-18860 is a vulnerability in Rapid7 Velociraptor affecting multi-tenant deployments. It allows administrators of child organizations to delete other organizations by exploiting improper permission checks. The flaw arises because the server checks ORG_ADMIN permissions within the calling org instead of the ROOT org, enabling privilege escalation within the deployment.

Join the discussion
CVE-2026-18636: CWE-288 Authentication bypass using an alternate path or channel in Rapid7 VelociraptorCVE-2026-18636
0

CVE-2026-18636 is an authentication bypass vulnerability in Rapid7 Velociraptor's gRPC API VFSGetBuffer endpoint. The endpoint allows reading files from the datastore and uses a prefix check to block access to sensitive files and other organizations' data. However, this prefix check can be bypassed, enabling users with read permission in the ROOT organization to access files from other organizations where they lack permission. This vulnerability affects versions prior to 0.77.2 and has a medium severity rating with a CVSS score of 6.8.

Join the discussion
CVE-2026-17535: CWE-125 Out-of-bounds read in Rapid7 VelociraptorCVE-2026-17535
0

CVE-2026-17535 is a medium severity vulnerability in Rapid7 Velociraptor's NTFS parsing library. It involves out-of-bounds read and memory exhaustion issues triggered by maliciously crafted NTFS images. The vulnerability mainly affects scenarios where Velociraptor processes untrusted NTFS image files, such as dead disk forensics. Exploitation can cause application crashes leading to denial of service. No data confidentiality or integrity impact is reported. The vulnerability affects Velociraptor versions prior to 0.77.2. There is no confirmed patch or official remediation available at this time.

Join the discussion
CVE-2026-18635: CWE-863 in Rapid7 VelociraptorCVE-2026-18635
0

CVE-2026-18635 is a vulnerability in Rapid7 Velociraptor prior to version 0.77.2 where the VQL query() plugin incorrectly evaluates the IMPERSONATE permission against the caller's organization instead of the target organization. This flaw allows an administrator in one organization to impersonate a user in another organization without having the proper permission in that target organization.

Join the discussion
CVE-2026-18972: CWE-290 Authentication bypass by spoofing in Rapid7 VelociraptorCVE-2026-18972
0

An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a user with low privileges to administrator.

Join the discussion
CVE-2026-18348: CWE-863: Incorrect Authorization in Rapid7 VelociraptorCVE-2026-18348
0

Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst-role user can initiate attacker-controlled outbound network connections from the Velociraptor server, bypassing the NETWORK ACL permission boundary. This enables internal network reconnaissance via port oracle and potential data exfiltration to external endpoints.

Join the discussion

Showing 1 to 9 of 9 results

Filters:Package: pkg:github/Velociraptor
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses