CVE-2026-18638: Velociraptor server crash via the SetPassword API
Published on 2026-07-31
Vulnogram
CVSS · MEDIUM · 6.5 ⁄10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Scoring scenario:
GENERAL
attackVector:
NETWORK
attackComplexity:
LOW
privilegesRequired:
LOW
userInteraction:
NONE
scope:
UNCHANGED
confidentialityImpact:
NONE
integrityImpact:
NONE
availabilityImpact:
HIGH
Description
Any authenticated Velociraptor user — including one holding only the
readerrole — can terminate the entire server process with a single request, by calling SetPassword with a username that does not exist.Problem
CWE-476 NULL pointer dereference
Problem
CWE-703 Improper Check or Handling of Exceptional Conditions
Required configuration for exposure
The user must have at least reader permissions to the org before they can call the SetPassword API.
| Product | Affected |
|---|---|
| Rapid7 Velociraptor on
Linux
source repo Default status is unaffected |
before 0.77.2 |
Credits
- Mayank Rajput (https://github.com/hackelite01)
- The Mobasi Security team (https://mobasi.ai/sentinel )