PatchSiren cyber security CVE debrief
CVE-2026-18348 Rapid7 CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T06:17:13.287Z and has not been modified since then. The CVE-2026-18348 vulnerability is caused by a missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins in Velociraptor. An authenticated analyst-role user can exploit this vulnerability to initiate attacker-controlled outbound network connections from the Velociraptor server, bypassing the NETWORK ACL permission boundary. This allows for internal network reconnaissance via port oracle and potential data exfiltration to external endpoints. The CVSS score for this vulnerability is 4.1, indicating a MEDIUM severity level. Security teams and administrators responsible for Velociraptor server configurations and NETWORK ACLs should be aware of this vulnerability and take necessary actions to mitigate the risk.
- Vendor
- Rapid7
- Product
- Velociraptor
- CVSS
- MEDIUM 4.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-11
- Original CVE updated
- 2026-08-28
- Advisory published
- 2026-08-11
- Advisory updated
- 2026-08-28
Who should care
Security teams and administrators responsible for Velociraptor server configurations and NETWORK ACLs should be aware of this vulnerability and take necessary actions to mitigate the risk.
Technical summary
The CVE-2026-18348 vulnerability is caused by a missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins in Velociraptor. An authenticated analyst-role user can exploit this vulnerability to initiate attacker-controlled outbound network connections from the Velociraptor server, bypassing the NETWORK ACL permission boundary. This allows for internal network reconnaissance via port oracle and potential data exfiltration to external endpoints. The CVSS score for this vulnerability is 4.1, indicating a MEDIUM severity level.
Defensive priority
Authenticated users with analyst role can initiate outbound network connections, bypassing NETWORK ACLs, enabling internal reconnaissance and potential data exfiltration.
Recommended defensive actions
- Inventory and assess Velociraptor server configurations and NETWORK ACLs.
- Restrict analyst-role user permissions to minimize potential impact.
- Monitor Velociraptor server logs for suspicious outbound connections.
- Implement compensating controls to detect and prevent data exfiltration.
- Apply vendor remediation when available.
Evidence notes
The CVE-2026-18348 record indicates a missing authorization check in Velociraptor's upload_azure, upload_sftp, and upload_smb VQL plugins. An authenticated analyst-role user can initiate attacker-controlled outbound network connections from the Velociraptor server, bypassing the NETWORK ACL permission boundary. This enables internal network reconnaissance via port oracle and potential data exfiltration to external endpoints. The CVSS score is 4.1, and the severity is MEDIUM.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-18348 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-18348
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-18348 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18348
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/Velocidex/velociraptor/commit/48824fb51a2bdba832abc281e719ecbed74736df
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.