PT-2026-33112 · Unknown · Velociraptor

Faisal Alhumaid

·

Published

2026-04-15

·

Updated

2026-04-16

·

CVE-2026-6290

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Velociraptor versions prior to 0.76.3
Description A flaw in the query() plugin allows an authenticated GUI user to access all organizations using their current ACL token. By utilizing the query() plugin within a notebook cell, a user with access to one organization can execute VQL queries on other organizations they are not authorized to access. In such cases, the user maintains the same permissions in the target organization as they have in the organization where the notebook is located.
Recommendations Update to version 0.76.3 or later.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-6290
GHSA-HV5G-26JG-PC45

Affected Products

Velociraptor