[NEW] [high] Rapid7 Velociraptor: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in Rapid7 Velociraptor to gain elevated privileges, including administrator rights, bypass security measures, conduct spoofing and cross-site scripting attacks, manipulate data, disclose sensitive information, or trigger a denial-of-service condition.
CSIRTS triage
- What
- Multiple vulnerabilities allow privilege escalation, security bypass, cross-site scripting, spoofing, data manipulation, information disclosure, and denial-of-service in Rapid7 Velociraptor.
- Who is affected
- All Velociraptor deployments are affected by multiple attack vectors.
- Urgency
- Critical; multiple severe vulnerabilities affecting authentication, authorization, and system availability.
- Action
- Update Rapid7 Velociraptor to the latest patched version immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Velociraptor
Get an email when a new Velociraptor advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2728
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-153710.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-175350.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-183480.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-186350.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-186360.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-186380.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-186390.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-186400.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-186520.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-188600.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-15371 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-17535 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-18348 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-18635 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-18636 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-18638 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-18639 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-18640 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-18652 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-18860 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-18972 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64951 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64952 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64954 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64955 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64953 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highCVE-2026-15371: Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type tak…nvd
- mediumCVE-2026-64955: When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters a…nvd
- mediumCVE-2026-64952: The hunt_delete() VQL function allows deleting hunts. Velociraptor misapplied the permission c…nvd
- lowCVE-2026-64951: A rogue Velociraptor client can upload a malformed sparse file such that if the GUI attempts t…nvd
- mediumCVE-2026-18652: Velociraptor allows reading Stacked result sets from the GUI. Velociraptor's multi-tenant desi…nvd
- highCVE-2026-64954: Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to sch…nvd
- unknownRapid7 security advisory (AV26-801)cccs
- highCVE-2026-18640: The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated us…nvd
- highCVE-2026-18639: When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim…nvd
- mediumCVE-2026-18638: Any authenticated Velociraptor user — including one holding only the readerrole — can terminat…nvd
- highCVE-2026-18860: Velociraptor allows multi-tenant deployments named "Orgs". By default Velociraptor, uses the R…nvd
- mediumCVE-2026-18636: The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the data…nvd
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] Linux Kernel: Multiple vulnerabilities2026-08-25
- medium[NEW] [medium] libTIFF: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Contao: Multiple Vulnerabilities2026-08-25
- medium[NEW] [medium] Django: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Red Hat Enterprise Linux (Apicurio Registry): Multiple Vulnerabilities2026-08-25