CVE-2026-18636

Source
https://cve.org/CVERecord?id=CVE-2026-18636
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18636.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-18636
Published
2026-08-11T14:40:12.322Z
Modified
2026-08-13T04:02:20.627939771Z
Severity
  • 6.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N CVSS Calculator
Summary
Velociraptor VFSGetBuffer API path deny list bypass
Details

The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users from reading sensitive files or accessing other orgs, the requested path is prefix checked against a list of denied prefixes. This prefix check can be bypassed allowing a user to access usually denied files. If the user has read permission in the ROOT org, this allows access to other orgs, in which the user may not have permission.

Database specific
{
    "cwe_ids": [
        "CWE-288"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18636.json",
    "cna_assigner": "rapid7"
}
References

Affected packages

Git / github.com/velocidex/velociraptor

Affected ranges

Type
GIT
Repo
https://github.com/velocidex/velociraptor
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.77.2"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

0.*
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
v0.*
v0.1
v0.3.0
v0.3.1
v0.3.2
v0.3.3
v0.3.4
v0.3.5
v0.3.6
v0.3.7
v0.3.8
v0.3.9
v0.4.0
v0.4.1
v0.4.2
v0.4.3
v0.4.4
v0.4.5
v0.4.6
v0.4.7
v0.4.8
v0.4.9
v0.5.0
v0.5.1
v0.5.2
v0.5.3
v0.5.4
v0.5.5
v0.5.5-1
v0.5.6
v0.5.7
v0.5.8-rc1
v0.5.9-rc1
v0.6.0-rc1
v0.6.1-rc1
v0.6.2-rc1
v0.6.3-rc1
v0.6.4-rc1
v0.6.7-rc1
v0.6.8-rc1
v0.7.0
v0.7.0-rc1
v0.72
v0.73
v0.74
v0.75
v0.76.1-rc1
v0.77.1
v0.77.1-rc1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18636.json"