Junglewise Threat Intelligence

CVE-2026-64954: Velociraptor privilege escalation via VQL query authorization bypass

CVE-2026-64954 · Severity: high · CVSS 8.2 · Published 2026-08-12

Technologies: Velocidex Velociraptor. Vendors: Velocidex.

Executive brief

Velociraptor is a digital forensics and incident response platform that allows authorized users to collect data from systems via VQL queries and notebooks. The vulnerability allows analysts (who can run arbitrary VQL queries) to bypass permission checks and schedule new data collections, an action normally restricted to investigators. This enables privilege escalation from analyst to investigator role, allowing lower-privileged users to perform higher-privileged actions.

Technical details

The vulnerability exists in Velociraptor's permission enforcement for the collect_client() function. Normally, scheduling new collections requires the COLLECT_CLIENT permission, which is enforced at the API level. However, the vulnerability stems from insufficient authorization checks when a VQL query resets the authorization provider. An analyst with permission to run arbitrary VQL queries in notebooks can trigger this code path to bypass the COLLECT_CLIENT permission check, allowing them to schedule collections without proper authorization. The attack requires the ability to execute VQL queries (typically available to users with the analyst role) but no network access or special user interaction is needed beyond running the malicious query. Patches are available in version 0.77.2 and later.

Affected products

  • Velocidex Velociraptor before 0.77.2

Timeline

  • 2026-08-12: disclosed
  • 2026-07-19: patched: Fix applied in version 0.77.2

References

Related threats