Sceawere
Vulnerability Detail
CVE-2026-78413UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Velociraptor Artifact Privilege Escalation
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.5
- Creation Date
- 3h ago
- Vendor
- Rapid7
- Product
- Velociraptor
- Attack Type
- CWE-276 Incorrect default permissions
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L
- Attack Complexity
- HIGH
Narrative and Response
Description
Velociraptor allows collection of VQL queries packaged into Artifacts from endpoints. These artifacts can be used to do anything and usually run with elevated permissions. To limit access to some dangerous artifact, Velociraptor allows for those to require high permissions like EXECVE to launch. The `Windows.Sysinternals.SysmonLogForward` is a monitoring artifact used to forward sysmon events to the server. The artifact allows the user to specify an arbitrary binary path as a parameter, and did not enforce an additional required permission, allowing users with COLLECT_CLIENT permissions (normally given by the "Investigator" role) to collect it from endpoints and run a different binary program than the installed sysmon binary. To successfully exploit this vulnerability the user must already have access to collect artifacts from the endpoint (i.e. have the COLLECT_CLIENT given typically by the "Investigator" role).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.5",
"pubDate": "2026-10-05T18:17:37.383Z",
"pubdate": "2026-10-05T18:17:37.383Z",
"executiveSummary": "This vulnerability is an Improper Authorization flaw within the Velociraptor artifact execution framework. It affects the Windows.Sysinternals.SysmonLogForward artifact, which failed to enforce mandatory elevated permissions required for executing arbitrary binary paths.\nThe vulnerability allows an authenticated user with the COLLECT_CLIENT permission—typically assigned to the Investigator role—to achieve local privilege escalation or arbitrary code execution with elevated system privileges. By manipulating the binary path parameter within the artifact, an attacker can bypass intended security controls to execute unauthorized binaries on target endpoints.\nThe risk implication is significant as it permits lateral movement or persistence within the environment by leveraging Velociraptor's trusted agent infrastructure. Successful exploitation requires existing, legitimate access to the Velociraptor management interface with the ability to initiate artifact collections on managed endpoints. This flaw underscores a failure to restrict access to sensitive execution primitives, effectively granting a lower-privileged user the capability to invoke high-risk system functions that should be reserved for administrative roles.",
"technicalDetails": "The root cause of the vulnerability lies in the insufficient permission validation logic within the Windows.Sysinternals.SysmonLogForward artifact. In the Velociraptor ecosystem, sensitive operations—particularly those involving the execution of external binaries—are gated by specific high-level permissions, such as the EXECVE permission. The design intent is to ensure that only administrators can leverage the agent to trigger binary execution.\nThe Windows.Sysinternals.SysmonLogForward artifact, designed for forwarding Sysmon logs, included a user-configurable parameter that accepted an arbitrary file system path to a binary. The implementation failed to include the necessary authorization check that would enforce the requirement of the EXECVE permission before proceeding with the execution of the specified binary path. Consequently, the artifact's logic accepted input without verifying whether the initiating user possessed the administrative context required to perform such actions.\nThe attack flow proceeds as follows: First, an attacker possessing the COLLECT_CLIENT permission navigates to the Velociraptor management console. Second, the attacker initiates a collection of the Windows.Sysinternals.SysmonLogForward artifact on a selected endpoint. During the configuration phase of the artifact collection, the attacker modifies the binary path parameter to point to a malicious executable or an existing system binary that the attacker wishes to run with the elevated service account permissions utilized by the Velociraptor client. Finally, when the endpoint agent processes the collection request, it executes the specified binary path under the security context of the Velociraptor agent service, which typically runs with SYSTEM or high-integrity privileges.\nThis vulnerability effectively elevates the capabilities of the Investigator role beyond their intended scope. By utilizing this artifact as a primitive for arbitrary code execution, an attacker can bypass the intended segregation of duties between standard investigation tasks and administrative host management. The impact is a complete compromise of the endpoint, as the attacker can execute arbitrary commands, install persistence mechanisms, or extract sensitive data, all while appearing to operate within the parameters of a standard Velociraptor investigation task."
}