CVE-2026-18635

Source
https://cve.org/CVERecord?id=CVE-2026-18635
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18635.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-18635
Published
2026-08-11T14:15:58Z
Modified
2026-08-30T03:30:50Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Velociraptor query plugin allows impersonation in other orgs
Details

Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able to run as a different user, the calling user needs to have the IMPERSONATE permission (usually only given to administrators). Velociraptor versions prior to 0.77.2 evaluate this permission against the caller's org instead of against the target org.

This allows an administrator in one org to impersonate another user in another org, in which they may not have the IMPERSONATE permission.

Database specific
{
    "cna_assigner": "rapid7",
    "cwe_ids": [
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18635.json"
}
References

Affected packages

Git / github.com/velocidex/velociraptor

Affected ranges

Type
GIT
Repo
https://github.com/velocidex/velociraptor
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.77.2"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

0.*
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
v0.*
v0.1
v0.3.0
v0.3.1
v0.3.2
v0.3.3
v0.3.4
v0.3.5
v0.3.6
v0.3.7
v0.3.8
v0.3.9
v0.4.0
v0.4.1
v0.4.2
v0.4.3
v0.4.4
v0.4.5
v0.4.6
v0.4.7
v0.4.8
v0.4.9
v0.5.0
v0.5.1
v0.5.2
v0.5.3
v0.5.4
v0.5.5
v0.5.5-1
v0.5.6
v0.5.7
v0.5.8-rc1
v0.5.9-rc1
v0.6.0-rc1
v0.6.1-rc1
v0.6.2-rc1
v0.6.3-rc1
v0.6.4-rc1
v0.6.7-rc1
v0.6.8-rc1
v0.7.0
v0.7.0-rc1
v0.72
v0.73
v0.74
v0.75
v0.76.1-rc1
v0.77.1
v0.77.1-rc1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18635.json"