PT-2026-33112 · Unknown · Velociraptor
Faisal Alhumaid
·
Published
2026-04-15
·
Updated
2026-04-16
·
CVE-2026-6290
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Velociraptor versions prior to 0.76.3
Description
A flaw in the
query() plugin allows an authenticated GUI user to access all organizations using their current ACL token. By utilizing the query() plugin within a notebook cell, a user with access to one organization can execute VQL queries on other organizations they are not authorized to access. In such cases, the user maintains the same permissions in the target organization as they have in the organization where the notebook is located.Recommendations
Update to version 0.76.3 or later.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Velociraptor