PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-64951 Rapid7 CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-12T10:17:20.063Z and has not been modified since then. CVE-2026-64951 is a Divide by Zero bug in the ShouldPadFile() function of the Velociraptor client. A rogue client can upload a malformed sparse file that, when expanded by the GUI, causes a panic and potentially crashes the server process. The vulnerability has a CVSS score of 3.5 and is considered Low severity. This issue can be mitigated by applying patches for the Velociraptor client to prevent malicious file uploads and restricting GUI access to trusted users. Evidence from official CVE Program record and NIST NVD detail page; limited detail on affected products and versions. Administrators should verify the integrity of uploaded files and monitor server process stability.

Vendor
Rapid7
Product
Velociraptor
CVSS
LOW 3.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-12
Original CVE updated
2026-08-28
Advisory published
2026-08-12
Advisory updated
2026-08-28

Who should care

Velociraptor server administrators and users with GUI access; security teams monitoring for potential service disruptions. These stakeholders should prioritize patching for GUI users and monitor server process stability and GUI usage for potential attacks. The vulnerability's low severity requires attention but not immediate action unless exposed to potential threats.

Technical summary

CVE-2026-64951 is a Divide by Zero bug in the ShouldPadFile() function of the Velociraptor client. A rogue client can upload a malformed sparse file that, when expanded by the GUI, causes a panic and potentially crashes the server process. The vulnerability has a CVSS score of 3.5 and is considered Low severity. This issue can be mitigated by applying patches for the Velociraptor client to prevent malicious file uploads and restricting GUI access to trusted users.

Defensive priority

Low-severity vulnerability with potential for service disruption; prioritize patching for GUI users.

Recommended defensive actions

  • Apply patch for Velociraptor client to prevent malicious file uploads
  • Restrict GUI access to trusted users to minimize attack surface
  • Monitor server process stability and GUI usage for potential attacks

Evidence notes

Evidence from official CVE Program record and NIST NVD detail page; limited detail on affected products and versions. The CVE record was published on 2026-08-12T10:17:20.063Z and has not been modified since then. A Divide by Zero bug in the ShouldPadFile() function of the Velociraptor client allows a rogue client to upload a malformed sparse file. When the GUI attempts to expand this file, it causes a panic that may crash the server process. The vulnerability has a CVSS score of 3.5 and is considered Low severity. Administrators should verify the integrity of uploaded files and monitor server process stability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-64951 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-64951

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-64951 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-64951

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.