Junglewise Threat Intelligence

CVE-2026-19584: Velociraptor VQL injection in notebook backup restore

CVE-2026-19584 · Severity: high · CVSS 7.7 · Published 2026-09-10

Technologies: Velocidex Velociraptor. Vendors: Velocidex.

Executive brief

Velociraptor is a digital forensics and incident response tool that analysts use to collect and analyze data from computer systems. A malicious user with notebook editing permissions can inject malicious queries into notebook backups, which execute with elevated privileges when the backup is restored, potentially compromising investigation integrity and enabling unauthorized access to sensitive forensic data.

Technical details

The vulnerability is a VQL (Velociraptor Query Language) injection in the notebook backup restoration feature. When Velociraptor restores a notebook from a backup, the notebook cell content is interpolated into a template without ACL (access control list) checks. A user with NOTEBOOK_EDITOR permission can plant a malicious VQL query in a notebook, and if that notebook's backup is subsequently restored, the injected query executes at elevated privileges. The attack requires the attacker to have NOTEBOOK_EDITOR permissions and requires an administrator or authorized user to restore the backup. A fix is available in Velociraptor version 0.77.2.

Affected products

  • Velocidex Velociraptor before 0.77.2

Timeline

  • 2026-09-10: disclosed: CVE published
  • 2026-08-10: patched: Fix merged in PR #4967, available in version 0.77.2

References

Related threats