CVE-2026-18348: Velociraptor NETWORK ACL bypass via upload_azure / upload_sftp / upload_smb VQL plugins
Published on 2026-07-31
Vulnogram
CVSS · MEDIUM · 4.1 ⁄10 · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
Scoring scenario:
GENERAL
attackVector:
NETWORK
attackComplexity:
LOW
privilegesRequired:
HIGH
userInteraction:
NONE
scope:
CHANGED
confidentialityImpact:
LOW
integrityImpact:
NONE
availabilityImpact:
NONE
Description
Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst-role user can initiate attacker-controlled outbound network connections from the Velociraptor server, bypassing the NETWORK ACL permission boundary. This enables internal network reconnaissance via port oracle and potential data exfiltration to external endpoints.
Problem
CWE-863: Incorrect Authorization
| Product | Affected |
|---|---|
| Rapid7 Velociraptor on
Linux
source repo Default status is unaffected |
before 0.77.2 |
Credits
- Hamad Alghamdi