{"id":"CVE-2026-19584","title":"Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature","summary":"Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a mali…","severity":"high","cvss":7.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N","cwe":["CWE-94","CWE-1336"],"vendor":"Rapid7","product":"Velociraptor","affected":["Velociraptor < 0.77.2"],"published":"2026-09-10","updated":"2026-09-11","sourceUpdated":"2026-09-11T04:17:34.343","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-19584","references":[{"url":"http://docs.velociraptor.app/announcements/advisories/cve-2026-19584/","label":"cve@rapid7.com"},{"url":"https://github.com/Velocidex/velociraptor/pull/4967","label":"cve@rapid7.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-10T00:00:00+00:00"},"ingestedAt":"2026-09-13T19:09:28.206Z","epss":0.0019,"epssPercentile":0.07621,"slug":"CVE-2026-19584","body":"## Overview\n\nVelociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a malicious user with NOTEBOOK_EDITOR permission to plant a VQL query which will be evaluated at elevated permissions if the notebook's backup is subsequently restored.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":42.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}