CVE-2026-18638: Velociraptor server crash via the SetPassword API

Published on 2026-07-31 Vulnogram
Description

Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server process with a single request, by calling SetPassword with a username that does not exist.

Problem CWE-476 NULL pointer dereference
Problem CWE-703 Improper Check or Handling of Exceptional Conditions
Required configuration for exposure The user must have at least reader permissions to the org before they can call the SetPassword API.
ProductAffected
Rapid7 Velociraptor on Linux
source repo
Default status is unaffected
before 0.77.2