CVE-2026-19583 CRITICAL

CVE-2026-19583: Velociraptor Required Permissions bypass by using client monitoring queries

Vendor Rapid7
Product Velociraptor
Weakness CWE-732
Published September 10, 2026
Last update September 11, 2026

CVSS base score

9.9/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L

What the vulnerability does

01Description

Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. However, no such check was implemented for client monitoring artifacts. Additionally there was no requirement that client monitoring artifacts carry the CLIENT_EVENTS type. This allows any user who can schedule client monitoring artifacts to also schedule otherwise restricted artifacts (such as Linux.Sys.BashShell).

Key dates

02Disclosure timeline

September 10, 2026 CVE published
September 11, 2026 Record updated