PatchSiren cyber security CVE debrief
CVE-2026-64954 Rapid7 CVE debrief
The CVE-2026-64954 vulnerability affects Velociraptor, allowing users with the 'analyst' role to schedule new collections, typically requiring the 'investigator' role. This is due to a lack of proper permission checks when running VQL queries that reset the authorization provider. Organizations using Velociraptor, especially those with users having the 'analyst' role, should be aware of this vulnerability and take steps to mitigate it. The CVE record was published on 2026-08-12T05:19:17.893Z and has not been modified since then. The vulnerability has a CVSS score of 8.2 and is considered HIGH severity. The exploitation of this vulnerability could lead to an escalation from an analyst to an investigator role.
- Vendor
- Rapid7
- Product
- Velociraptor
- CVSS
- HIGH 8.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-12
- Original CVE updated
- 2026-08-28
- Advisory published
- 2026-08-12
- Advisory updated
- 2026-08-28
Who should care
Organizations using Velociraptor, particularly those with users having the 'analyst' role, should be aware of this vulnerability and take steps to mitigate it. The vulnerability could lead to an escalation of privileges from an analyst to an investigator role, potentially allowing unauthorized collection scheduling. Users with the 'analyst' role should be cautious when running VQL queries, and administrators should review user roles and permissions to prevent exploitation. Additionally, organizations should prioritize patching and review user roles to prevent unauthorized collection scheduling. This vulnerability may impact Velociraptor deployments in various environments, including those with multiple user roles and complex permission structures. Users of Velociraptor should assess their exposure and take appropriate measures to protect their systems. This may involve reviewing and restricting VQL query execution permissions, enforcing COLLECT_CLIENT permission checks, and monitoring for unauthorized collection scheduling attempts. The CVE record provides further details on the vulnerability, and users should consult the official CVE Program record and NIST NVD detail page for more information. The vulnerability management and security teams should also be aware of this issue and plan for remediation accordingly. The affected product and its users are advised to take immediate action to prevent exploitation of this vulnerability. This may involve applying patches, updating configurations, or implementing compensating controls to mitigate the risk of exploitation. By taking these steps, organizations can help protect their Velociraptor deployments from potential attacks. The CVE-2026-64954 vulnerability highlights the importance of proper permission checks and user role management in preventing privilege escalation attacks. Users and administrators should remain vigilant and take proactive measures to prevent exploitation of this vulnerability. This includes staying informed about the latest security advisories and patches, as well as implementing robust security controls to protect against potential threats. The CVE-2026-64954 vulnerability serves as a reminder
Technical summary
The vulnerability allows a user with the 'analyst' role to schedule new collections, typically requiring the 'investigator' role, by exploiting the lack of proper permission checks when running VQL queries that reset the authorization provider. This could potentially lead to unauthorized collection scheduling. The affected product is Velociraptor, and the vulnerability is related to the execution of VQL queries in notebooks. The CVE description indicates that the COLLECT_CLIENT permission is not enforced in certain scenarios, allowing for the escalation of privileges.
Defensive priority
Organizations using Velociraptor should prioritize patching and review user roles to prevent unauthorized collection scheduling.
Recommended defensive actions
- Review and restrict VQL query execution permissions
- Enforce COLLECT_CLIENT permission checks for collection scheduling
- Monitor for unauthorized collection scheduling attempts
- Patch Velociraptor to the latest version
- Confirm whether affected Velociraptor deployments exist in managed environments and assign an owner for follow-up.
- Review compensating controls for exposed Velociraptor systems while remediation is scheduled and verified.
- Track exceptions, retest remediated Velociraptor assets, and close the item only after evidence is documented.
Evidence notes
The CVE description indicates that Velociraptor allows scheduling new collections via VQL queries in notebooks without properly enforcing the COLLECT_CLIENT permission when the user can run a VQL query which resets the authorization provider. This allows a user who can run arbitrary VQL to launch new collections.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-64954 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-64954
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-64954 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-64954
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/Velocidex/velociraptor/commit/d7de958e846d3742a7a3a8538fd463e4f12fc528
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.