CVE-2026-19584 HIGH

CVE-2026-19584: Velociraptor VQL injection during notebook restore from backup

Vendor Rapid7
Product Velociraptor
Weakness CWE-1336
Published September 10, 2026
Last update September 11, 2026

CVSS base score

7.7/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N

What the vulnerability does

01Description

Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a malicious user with NOTEBOOK_EDITOR permission to plant a VQL query which will be evaluated at elevated permissions if the notebook's backup is subsequently restored.

Key dates

02Disclosure timeline

September 10, 2026 CVE published
September 11, 2026 Record updated

Related vulnerabilities

04Related CVE