Sceawere

Vulnerability Detail

CVE-2026-78413UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Velociraptor Artifact Privilege Escalation

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
3h ago
Vendor
Rapid7
Product
Velociraptor
Attack Type
CWE-276 Incorrect default permissions
Vector String
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L
Attack Complexity
HIGH

Narrative and Response

Description

Velociraptor allows collection of VQL queries packaged into Artifacts from endpoints. These artifacts can be used to do anything and usually run with elevated permissions. To limit access to some dangerous artifact, Velociraptor allows for those to require high permissions like EXECVE to launch. The `Windows.Sysinternals.SysmonLogForward` is a monitoring artifact used to forward sysmon events to the server. The artifact allows the user to specify an arbitrary binary path as a parameter, and did not enforce an additional required permission, allowing users with COLLECT_CLIENT permissions (normally given by the "Investigator" role) to collect it from endpoints and run a different binary program than the installed sysmon binary. To successfully exploit this vulnerability the user must already have access to collect artifacts from the endpoint (i.e. have the COLLECT_CLIENT given typically by the "Investigator" role).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-10-05T18:17:37.383Z",
  "pubdate": "2026-10-05T18:17:37.383Z",
  "executiveSummary": "This vulnerability is an Improper Authorization flaw within the Velociraptor artifact execution framework. It affects the Windows.Sysinternals.SysmonLogForward artifact, which failed to enforce mandatory elevated permissions required for executing arbitrary binary paths.\nThe vulnerability allows an authenticated user with the COLLECT_CLIENT permission—typically assigned to the Investigator role—to achieve local privilege escalation or arbitrary code execution with elevated system privileges. By manipulating the binary path parameter within the artifact, an attacker can bypass intended security controls to execute unauthorized binaries on target endpoints.\nThe risk implication is significant as it permits lateral movement or persistence within the environment by leveraging Velociraptor's trusted agent infrastructure. Successful exploitation requires existing, legitimate access to the Velociraptor management interface with the ability to initiate artifact collections on managed endpoints. This flaw underscores a failure to restrict access to sensitive execution primitives, effectively granting a lower-privileged user the capability to invoke high-risk system functions that should be reserved for administrative roles.",
  "technicalDetails": "The root cause of the vulnerability lies in the insufficient permission validation logic within the Windows.Sysinternals.SysmonLogForward artifact. In the Velociraptor ecosystem, sensitive operations—particularly those involving the execution of external binaries—are gated by specific high-level permissions, such as the EXECVE permission. The design intent is to ensure that only administrators can leverage the agent to trigger binary execution.\nThe Windows.Sysinternals.SysmonLogForward artifact, designed for forwarding Sysmon logs, included a user-configurable parameter that accepted an arbitrary file system path to a binary. The implementation failed to include the necessary authorization check that would enforce the requirement of the EXECVE permission before proceeding with the execution of the specified binary path. Consequently, the artifact's logic accepted input without verifying whether the initiating user possessed the administrative context required to perform such actions.\nThe attack flow proceeds as follows: First, an attacker possessing the COLLECT_CLIENT permission navigates to the Velociraptor management console. Second, the attacker initiates a collection of the Windows.Sysinternals.SysmonLogForward artifact on a selected endpoint. During the configuration phase of the artifact collection, the attacker modifies the binary path parameter to point to a malicious executable or an existing system binary that the attacker wishes to run with the elevated service account permissions utilized by the Velociraptor client. Finally, when the endpoint agent processes the collection request, it executes the specified binary path under the security context of the Velociraptor agent service, which typically runs with SYSTEM or high-integrity privileges.\nThis vulnerability effectively elevates the capabilities of the Investigator role beyond their intended scope. By utilizing this artifact as a primitive for arbitrary code execution, an attacker can bypass the intended segregation of duties between standard investigation tasks and administrative host management. The impact is a complete compromise of the endpoint, as the attacker can execute arbitrary commands, install persistence mechanisms, or extract sensitive data, all while appearing to operate within the parameters of a standard Velociraptor investigation task."
}
CVE-2026-78413: Velociraptor Artifact Privilege Escalation (MEDIUM Severity, CVSS: 5.5) | Sceawere