CVE-2026-77798: Velociraptor Authenticated Denial of Service
Published on 2026-09-21
Vulnogram
CVSS · MEDIUM · 6.5 ⁄10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Scoring scenario:
GENERAL
attackVector:
NETWORK
attackComplexity:
LOW
privilegesRequired:
LOW
userInteraction:
NONE
scope:
UNCHANGED
confidentialityImpact:
NONE
integrityImpact:
NONE
availabilityImpact:
HIGH
Description
Velociraptor contains a deadlock condition that may be triggered by authenticated users. The issue stems from a lock management bug in the user management module.
Problem
CWE-833 Deadlock
| Product | Affected |
|---|---|
| Rapid7 Velociraptor on
Linux
source repo Default status is unaffected |
before 0.77.2 |
Credits
- Yuval Miller and Leon Kayaliev