Sceawere

Vulnerability Detail

CVE-2026-18348UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Velociraptor Authorization Bypass Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.1
Creation Date
4h ago
Vendor
Rapid7
Product
Velociraptor
Attack Type
CWE-863: Incorrect Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst-role user can initiate attacker-controlled outbound network connections from the Velociraptor server, bypassing the NETWORK ACL permission boundary. This enables internal network reconnaissance via port oracle and potential data exfiltration to external endpoints.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.1",
  "pubDate": "2026-08-11T06:17:13.287Z",
  "pubdate": "2026-08-11T06:17:13.287Z",
  "executiveSummary": "A missing authorization check vulnerability exists within the Velociraptor server, specifically affecting the upload_azure, upload_sftp, and upload_smb VQL plugins. This flaw allows an authenticated user assigned to the analyst role to initiate attacker-controlled outbound network connections directly from the Velociraptor server infrastructure, effectively bypassing configured NETWORK ACL permission boundaries. The primary impact of this security deficiency includes unauthorized internal network reconnaissance via port oracle techniques and the potential for unauthorized data exfiltration to external endpoints under the control of an adversary. Exploitation of this vulnerability requires prior authentication with an analyst-role privilege level. The risk implication is significant as it compromises internal network segmentation and boundary controls enforced by the application layer. No specific version numbers or external identifiers beyond the provided description were referenced in the input data.",
  "technicalDetails": "The root cause of this vulnerability lies in the absence of proper authorization and permission validations within the VQL (Velociraptor Query Language) plugin execution context. Specifically, the vulnerable components comprise the upload_azure, upload_sftp, and upload_smb plugins, which handle remote data transfers to external or cloud-based storage services.\nThe vulnerability requires an adversary to possess an authenticated session with the analyst role. Because the affected VQL plugins fail to enforce rigorous access controls and network permission boundaries, an authenticated user can craft and execute specific VQL queries that leverage these upload functions. Upon execution, the Velociraptor server processes the request and initiates outbound network connections to arbitrary, attacker-controlled destinations specified within the VQL query parameters.\nThe attack flow proceeds as follows: First, the authenticated analyst-role user authenticates to the Velociraptor server interface. Second, the user submits a specially crafted VQL query invoking one of the vulnerable plugins (upload_azure, upload_sftp, or upload_smb) with parameters targeting arbitrary internal or external network destinations. Third, the Velociraptor server executes the query, bypassing the expected NETWORK ACL permission boundaries due to the missing authorization check. Fourth, the server establishes the outbound network connection.\nThis behavior enables malicious payload behavior such as internal network reconnaissance, allowing the attacker to act as a port oracle by probing internal hosts and services that are otherwise inaccessible from the external perimeter. Furthermore, it facilitates data exfiltration by enabling the direct transfer of sensitive server-accessible data to external endpoints controlled by the attacker. Post-exploitation impact encompasses unauthorized visibility into internal network topologies and the risk of data compromise."
}
CVE-2026-18348: Velociraptor Authorization Bypass Vulnerability (MEDIUM Severity, CVSS: 4.1) - Sceawere