PatchSiren cyber security CVE debrief
CVE-2026-18652 Rapid7 CVE debrief
Velociraptor, a tool used for incident response and threat hunting, contains a vulnerability that allows reading Stacked result sets from the GUI. This issue arises from Velociraptor's multi-tenant design, which stores sub-orgs within the datastore directory. The path requested by the GUI is not correctly checked against the prefix deny list, allowing result sets to be read from denied prefixes. Specifically, a user with read access to the root org can access result sets from child orgs. This vulnerability can have significant operational impacts, including unauthorized access to sensitive information. To address this, organizations should verify Velociraptor configurations, ensure proper access controls are in place, and monitor Velociraptor logs for unauthorized access attempts. The CVE record and vendor guidance should be reviewed to validate affected scope, severity, and necessary actions to protect deployments. Compensating controls, monitoring, and asset inventory are essential in addressing this vulnerability and protecting against potential unauthorized access to result sets.
- Vendor
- Rapid7
- Product
- Velociraptor
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-12
- Original CVE updated
- 2026-08-24
- Advisory published
- 2026-08-12
- Advisory updated
- 2026-08-24
Who should care
Organizations using Velociraptor, particularly those with multi-tenant setups, should be aware of this vulnerability and take steps to mitigate it. This includes verifying Velociraptor configurations, ensuring proper access controls are in place, and monitoring Velociraptor logs for unauthorized access attempts. Additionally, operators, platform administrators, vulnerability management teams, and security teams should review the official CVE record and vendor guidance to understand the affected scope, severity, and necessary actions to protect their deployments. They should also confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Compensating controls should be reviewed for exposed systems while remediation is scheduled and verified, and exceptions should be tracked, retested, and remediated as necessary. Monitoring, detection, and logs for exposed assets should be checked for extra review, and the integrity of Velociraptor deployments should be verified, particularly in multi-tenant setups. Asset inventory and rollback/change windows should also be considered in the remediation process. Source tracking and exposure review are crucial in ensuring the vulnerability is properly addressed. Overall, a comprehensive review of the vulnerability and its impact on the organization is necessary to ensure proper mitigation and protection of Velociraptor deployments. This may involve coordinating with vendors for patch guidance and tracking exceptions and retesting remediated assets to close the item only after evidence is documented. The CVE record and vendor guidance should be reviewed to validate affected scope, severity, and necessary actions to protect deployments. Compensating controls, monitoring, and asset inventory are essential in addressing this vulnerability and protecting against potential unauthorized access to result sets. The vulnerability management team should prioritize this vulnerability and work with the security team to ensure proper mitigation and protection of Velociraptor deployments. The security team should also review the official advisory or CVE record to validate affected scope, and the
Technical summary
Velociraptor's multi-tenant design stores sub orgs within the datastore directory. The path requested by the GUI is not correctly checked against the prefix deny list, allowing result sets to read from denied prefixes. A user with read access to the root org can access result sets from child orgs. This vulnerability can be mitigated by verifying Velociraptor configurations, ensuring proper access controls are in place, and monitoring Velociraptor logs for unauthorized access attempts. It is also essential to review compensating controls for exposed systems while remediation is scheduled and verified.
Defensive priority
Organizations using Velociraptor should verify their configurations and ensure proper access controls are in place to mitigate potential unauthorized access to result sets.
Recommended defensive actions
- Verify Velociraptor configurations to ensure proper access controls are in place.
- Restrict access to result sets based on organizational roles and permissions.
- Monitor Velociraptor logs for unauthorized access attempts.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the official CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
Evidence notes
The CVE record indicates that Velociraptor allows reading Stacked result sets from the GUI, with a user having read access to the root org able to access result sets from child orgs due to improper path checking against the prefix deny list. Organizations should verify their configurations and ensure proper access controls are in place to mitigate potential unauthorized access to result sets. This may involve reviewing Velociraptor logs for unauthorized access attempts and restricting access to result sets based on organizational roles and permissions. Additionally, defenders should verify the integrity of their Velociraptor deployments, particularly in multi-tenant setups, and review the official CVE record for affected scope, severity, and vendor guidance.
Official resources
-
CVE-2026-18652 CVE record
CVE.org
-
CVE-2026-18652 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-12T10:17:16.940Z and has not been modified since then.