PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-64954 Rapid7 CVE debrief

The CVE-2026-64954 vulnerability affects Velociraptor, allowing users with the 'analyst' role to schedule new collections, typically requiring the 'investigator' role. This is due to a lack of proper permission checks when running VQL queries that reset the authorization provider. Organizations using Velociraptor, especially those with users having the 'analyst' role, should be aware of this vulnerability and take steps to mitigate it. The CVE record was published on 2026-08-12T05:19:17.893Z and has not been modified since then. The vulnerability has a CVSS score of 8.2 and is considered HIGH severity. The exploitation of this vulnerability could lead to an escalation from an analyst to an investigator role.

Vendor
Rapid7
Product
Velociraptor
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-12
Original CVE updated
2026-08-28
Advisory published
2026-08-12
Advisory updated
2026-08-28

Who should care

Organizations using Velociraptor, particularly those with users having the 'analyst' role, should be aware of this vulnerability and take steps to mitigate it. The vulnerability could lead to an escalation of privileges from an analyst to an investigator role, potentially allowing unauthorized collection scheduling. Users with the 'analyst' role should be cautious when running VQL queries, and administrators should review user roles and permissions to prevent exploitation. Additionally, organizations should prioritize patching and review user roles to prevent unauthorized collection scheduling. This vulnerability may impact Velociraptor deployments in various environments, including those with multiple user roles and complex permission structures. Users of Velociraptor should assess their exposure and take appropriate measures to protect their systems. This may involve reviewing and restricting VQL query execution permissions, enforcing COLLECT_CLIENT permission checks, and monitoring for unauthorized collection scheduling attempts. The CVE record provides further details on the vulnerability, and users should consult the official CVE Program record and NIST NVD detail page for more information. The vulnerability management and security teams should also be aware of this issue and plan for remediation accordingly. The affected product and its users are advised to take immediate action to prevent exploitation of this vulnerability. This may involve applying patches, updating configurations, or implementing compensating controls to mitigate the risk of exploitation. By taking these steps, organizations can help protect their Velociraptor deployments from potential attacks. The CVE-2026-64954 vulnerability highlights the importance of proper permission checks and user role management in preventing privilege escalation attacks. Users and administrators should remain vigilant and take proactive measures to prevent exploitation of this vulnerability. This includes staying informed about the latest security advisories and patches, as well as implementing robust security controls to protect against potential threats. The CVE-2026-64954 vulnerability serves as a reminder

Technical summary

The vulnerability allows a user with the 'analyst' role to schedule new collections, typically requiring the 'investigator' role, by exploiting the lack of proper permission checks when running VQL queries that reset the authorization provider. This could potentially lead to unauthorized collection scheduling. The affected product is Velociraptor, and the vulnerability is related to the execution of VQL queries in notebooks. The CVE description indicates that the COLLECT_CLIENT permission is not enforced in certain scenarios, allowing for the escalation of privileges.

Defensive priority

Organizations using Velociraptor should prioritize patching and review user roles to prevent unauthorized collection scheduling.

Recommended defensive actions

  • Review and restrict VQL query execution permissions
  • Enforce COLLECT_CLIENT permission checks for collection scheduling
  • Monitor for unauthorized collection scheduling attempts
  • Patch Velociraptor to the latest version
  • Confirm whether affected Velociraptor deployments exist in managed environments and assign an owner for follow-up.
  • Review compensating controls for exposed Velociraptor systems while remediation is scheduled and verified.
  • Track exceptions, retest remediated Velociraptor assets, and close the item only after evidence is documented.

Evidence notes

The CVE description indicates that Velociraptor allows scheduling new collections via VQL queries in notebooks without properly enforcing the COLLECT_CLIENT permission when the user can run a VQL query which resets the authorization provider. This allows a user who can run arbitrary VQL to launch new collections.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-64954 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-64954

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-64954 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-64954

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.