Tag
#Velociraptor
Critical Vulnerability in Velociraptor: CVE-2026-19583
A critical vulnerability (CVE-2026-19583) with a CVSS score of 9.9 has been discovered in Velociraptor, a widely used security tool. This vulnerability allows any user who can schedule client monitoring artifacts to also schedule otherwise restricted artifacts, potentially leading to arbitrary command execution on endpoints. The vulnerability affects Velociraptor versions less than 0.77.2 and has a high impact on confidentiality, integrity, and availability. Immediate patching is recommended.
Critical Vulnerability in Velociraptor: CVE-2026-19200
A critical vulnerability (CVE-2026-19200, CVSS 8.9) in Velociraptor allows attackers with NOTEBOOK_EDIT permission to overwrite existing artifacts without required permissions, potentially leading to high impact on confidentiality and integrity. Affected versions are Velociraptor < 0.77.2 on Linux and Windows. Immediate mitigation is required.
Understanding and Defending Against CVE-2026-15371: A JavaScript XSS Vulnerability in Velociraptor
CVE-2026-15371 is a high-severity vulnerability in Velociraptor, a security tool used for endpoint monitoring and response. The vulnerability allows an attacker to inject malicious JavaScript code via a crafted URL, leading to a cross-site scripting (XSS) attack. This vulnerability has a CVSS score of 8.1, indicating a high level of severity. Understanding and mitigating this vulnerability is crucial to prevent potential attacks.
Understanding and Defending Against CVE-2026-18860: A Critical Vulnerability in Velociraptor
CVE-2026-18860 is a high-severity vulnerability in Velociraptor, a multi-tenant deployment platform, that allows administrators in child organizations to delete other organizations due to incorrect permission checks. This vulnerability has a CVSS score of 8.7 and requires immediate attention. The goal of this analysis is to provide a deep understanding of the threat and teach defensive thinking.