PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-18348 Rapid7 CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T06:17:13.287Z and has not been modified since then. The CVE-2026-18348 vulnerability is caused by a missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins in Velociraptor. An authenticated analyst-role user can exploit this vulnerability to initiate attacker-controlled outbound network connections from the Velociraptor server, bypassing the NETWORK ACL permission boundary. This allows for internal network reconnaissance via port oracle and potential data exfiltration to external endpoints. The CVSS score for this vulnerability is 4.1, indicating a MEDIUM severity level. Security teams and administrators responsible for Velociraptor server configurations and NETWORK ACLs should be aware of this vulnerability and take necessary actions to mitigate the risk.

Vendor
Rapid7
Product
Velociraptor
CVSS
MEDIUM 4.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-11
Original CVE updated
2026-08-28
Advisory published
2026-08-11
Advisory updated
2026-08-28

Who should care

Security teams and administrators responsible for Velociraptor server configurations and NETWORK ACLs should be aware of this vulnerability and take necessary actions to mitigate the risk.

Technical summary

The CVE-2026-18348 vulnerability is caused by a missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins in Velociraptor. An authenticated analyst-role user can exploit this vulnerability to initiate attacker-controlled outbound network connections from the Velociraptor server, bypassing the NETWORK ACL permission boundary. This allows for internal network reconnaissance via port oracle and potential data exfiltration to external endpoints. The CVSS score for this vulnerability is 4.1, indicating a MEDIUM severity level.

Defensive priority

Authenticated users with analyst role can initiate outbound network connections, bypassing NETWORK ACLs, enabling internal reconnaissance and potential data exfiltration.

Recommended defensive actions

  • Inventory and assess Velociraptor server configurations and NETWORK ACLs.
  • Restrict analyst-role user permissions to minimize potential impact.
  • Monitor Velociraptor server logs for suspicious outbound connections.
  • Implement compensating controls to detect and prevent data exfiltration.
  • Apply vendor remediation when available.

Evidence notes

The CVE-2026-18348 record indicates a missing authorization check in Velociraptor's upload_azure, upload_sftp, and upload_smb VQL plugins. An authenticated analyst-role user can initiate attacker-controlled outbound network connections from the Velociraptor server, bypassing the NETWORK ACL permission boundary. This enables internal network reconnaissance via port oracle and potential data exfiltration to external endpoints. The CVSS score is 4.1, and the severity is MEDIUM.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-18348 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-18348

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-18348 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18348

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.